CVE-2001-0775
xloadimage 4.1 - Remote Buffer Overflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attackers to execute arbitrary code via a FACES format image containing a long (1) Firstname or (2) Lastname field.
Tavis Ormandy of the Gentoo Linux Security Audit Team has reported that xli and xloadimage contain a flaw in the handling of compressed images, where shell meta-characters are not adequately escaped. Rob Holland of the Gentoo Linux Security Audit Team has reported that an xloadimage vulnerability in the handling of Faces Project images discovered by zen-parse in 2001 remained unpatched in xli. Additionally, it has been reported that insufficient validation of image properties in xli could potentially result in buffer management errors. Versions less than 4.1-r2 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2001-10-12 CVE Reserved
- 2001-10-12 CVE Published
- 2017-11-15 First Exploit
- 2024-08-08 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://www.iss.net/security_center/static/6821.php | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/20998 | 2017-11-15 | |
http://www.securityfocus.com/archive/1/195823 | 2024-08-08 | |
http://www.securityfocus.com/bid/3006 | 2024-08-08 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2001/dsa-069 | 2016-05-20 | |
http://www.debian.org/security/2005/dsa-695 | 2016-05-20 | |
http://www.gentoo.org/security/en/glsa/glsa-200503-05.xml | 2016-05-20 | |
http://www.novell.com/linux/security/advisories/2001_024_xli_txt.html | 2016-05-20 | |
http://www.redhat.com/support/errata/RHSA-2001-088.html | 2016-05-20 | |
https://access.redhat.com/security/cve/CVE-2001-0775 | 2001-07-09 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1616616 | 2001-07-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Xli Search vendor "Xli" | Xli Search vendor "Xli" for product "Xli" | 1.16 Search vendor "Xli" for product "Xli" and version "1.16" | - |
Affected
| ||||||
Xli Search vendor "Xli" | Xli Search vendor "Xli" for product "Xli" | 1.17 Search vendor "Xli" for product "Xli" and version "1.17" | - |
Affected
| ||||||
Xloadimage Search vendor "Xloadimage" | Xloadimage Search vendor "Xloadimage" for product "Xloadimage" | 4.1 Search vendor "Xloadimage" for product "Xloadimage" and version "4.1" | - |
Affected
|