LibXpm Integer Overflow in 'lib/scan.c' May Let Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1013339
|
|
SecurityTracker URL: http://securitytracker.com/id?1013339
|
|
CVE Reference: CAN-2005-0605
(Links to External Site)
|
Date: Mar 1 2005
|
Impact: Execution of arbitrary code via network, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Description: An integer overflow vulnerability was reported in libXpm. A remote user may be able to cause arbitrary code to be executed.
The 'lib/scan.c' code does not properly validate user-supplied data contained in image files. A remote user can create a specially
crafted image file that, when processed by the target user or application, will trigger the overflow and execute arbitrary code.
Negative
values in the 'image->bitmap_unit' variable can trigger the overflow.
|
Impact: A remote user can create an image that, when processed by libXpm, will execute arbitrary code on the target system.
|
Solution: A patch is available at:
https://bugs.freedesktop.org/attachment.cgi?id=1909
|
Vendor URL: www.x.org/ (Links to External Site)
|
Cause: Boundary error
|
Underlying OS: Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Tue, 1 Mar 2005 15:59:31 -0500
Subject: http://bugs.freedesktop.org/show_bug.cgi?id=1920
|
A vulnerability was reported in libXpm in the processing of images with certain
negative values.
A patch is available at:
https://bugs.freedesktop.org/attachment.cgi?id=1909
CVE: CAN-2005-0605
|
|