CVE-2004-0688
openmotif21 stack overflows in libxpm
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malformed XPM image file.
Múltiples desbordamientos de búfer en xpmParseColors en parse.c de libXpm anteriores a 6.8.1 permite a atacantes remotos ejecutar código arbitrario mediante un fichero de imagen XPM malformado.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2004-07-13 CVE Reserved
- 2004-09-24 CVE Published
- 2024-08-08 CVE Updated
- 2024-10-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (25)
URL | Tag | Source |
---|---|---|
http://ftp.x.org/pub/X11R6.8.0/patches/README.xorg-CAN-2004-0687-0688.patch | X_refsource_confirm | |
http://marc.info/?l=bugtraq&m=109530851323415&w=2 | Mailing List | |
http://scary.beasts.org/security/CESA-2004-003.txt | X_refsource_misc | |
http://secunia.com/advisories/20235 | Third Party Advisory | |
http://www.kb.cert.org/vuls/id/537878 | Third Party Advisory | |
http://www.us-cert.gov/cas/techalerts/TA05-136A.html | Third Party Advisory | |
http://www.vupen.com/english/advisories/2006/1914 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17416 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11796 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/bid/11196 | 2018-10-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
X.org Search vendor "X.org" | X11r6 Search vendor "X.org" for product "X11r6" | 6.7.0 Search vendor "X.org" for product "X11r6" and version "6.7.0" | - |
Affected
| ||||||
X.org Search vendor "X.org" | X11r6 Search vendor "X.org" for product "X11r6" | 6.8 Search vendor "X.org" for product "X11r6" and version "6.8" | - |
Affected
| ||||||
Xfree86 Project Search vendor "Xfree86 Project" | X11r6 Search vendor "Xfree86 Project" for product "X11r6" | 3.3.6 Search vendor "Xfree86 Project" for product "X11r6" and version "3.3.6" | - |
Affected
| ||||||
Xfree86 Project Search vendor "Xfree86 Project" | X11r6 Search vendor "Xfree86 Project" for product "X11r6" | 4.0 Search vendor "Xfree86 Project" for product "X11r6" and version "4.0" | - |
Affected
| ||||||
Xfree86 Project Search vendor "Xfree86 Project" | X11r6 Search vendor "Xfree86 Project" for product "X11r6" | 4.0.1 Search vendor "Xfree86 Project" for product "X11r6" and version "4.0.1" | - |
Affected
| ||||||
Xfree86 Project Search vendor "Xfree86 Project" | X11r6 Search vendor "Xfree86 Project" for product "X11r6" | 4.0.2.11 Search vendor "Xfree86 Project" for product "X11r6" and version "4.0.2.11" | - |
Affected
| ||||||
Xfree86 Project Search vendor "Xfree86 Project" | X11r6 Search vendor "Xfree86 Project" for product "X11r6" | 4.0.3 Search vendor "Xfree86 Project" for product "X11r6" and version "4.0.3" | - |
Affected
| ||||||
Xfree86 Project Search vendor "Xfree86 Project" | X11r6 Search vendor "Xfree86 Project" for product "X11r6" | 4.1.0 Search vendor "Xfree86 Project" for product "X11r6" and version "4.1.0" | - |
Affected
| ||||||
Xfree86 Project Search vendor "Xfree86 Project" | X11r6 Search vendor "Xfree86 Project" for product "X11r6" | 4.1.11 Search vendor "Xfree86 Project" for product "X11r6" and version "4.1.11" | - |
Affected
| ||||||
Xfree86 Project Search vendor "Xfree86 Project" | X11r6 Search vendor "Xfree86 Project" for product "X11r6" | 4.1.12 Search vendor "Xfree86 Project" for product "X11r6" and version "4.1.12" | - |
Affected
| ||||||
Xfree86 Project Search vendor "Xfree86 Project" | X11r6 Search vendor "Xfree86 Project" for product "X11r6" | 4.2.0 Search vendor "Xfree86 Project" for product "X11r6" and version "4.2.0" | - |
Affected
| ||||||
Xfree86 Project Search vendor "Xfree86 Project" | X11r6 Search vendor "Xfree86 Project" for product "X11r6" | 4.2.1 Search vendor "Xfree86 Project" for product "X11r6" and version "4.2.1" | - |
Affected
| ||||||
Xfree86 Project Search vendor "Xfree86 Project" | X11r6 Search vendor "Xfree86 Project" for product "X11r6" | 4.2.1 Search vendor "Xfree86 Project" for product "X11r6" and version "4.2.1" | errata |
Affected
| ||||||
Xfree86 Project Search vendor "Xfree86 Project" | X11r6 Search vendor "Xfree86 Project" for product "X11r6" | 4.3.0 Search vendor "Xfree86 Project" for product "X11r6" and version "4.3.0" | - |
Affected
| ||||||
Openbsd Search vendor "Openbsd" | Openbsd Search vendor "Openbsd" for product "Openbsd" | 3.4 Search vendor "Openbsd" for product "Openbsd" and version "3.4" | - |
Affected
| ||||||
Openbsd Search vendor "Openbsd" | Openbsd Search vendor "Openbsd" for product "Openbsd" | 3.5 Search vendor "Openbsd" for product "Openbsd" and version "3.5" | - |
Affected
| ||||||
Suse Search vendor "Suse" | Suse Linux Search vendor "Suse" for product "Suse Linux" | 8 Search vendor "Suse" for product "Suse Linux" and version "8" | enterprise_server |
Affected
| ||||||
Suse Search vendor "Suse" | Suse Linux Search vendor "Suse" for product "Suse Linux" | 8.1 Search vendor "Suse" for product "Suse Linux" and version "8.1" | - |
Affected
| ||||||
Suse Search vendor "Suse" | Suse Linux Search vendor "Suse" for product "Suse Linux" | 8.2 Search vendor "Suse" for product "Suse Linux" and version "8.2" | - |
Affected
| ||||||
Suse Search vendor "Suse" | Suse Linux Search vendor "Suse" for product "Suse Linux" | 9.0 Search vendor "Suse" for product "Suse Linux" and version "9.0" | - |
Affected
| ||||||
Suse Search vendor "Suse" | Suse Linux Search vendor "Suse" for product "Suse Linux" | 9.0 Search vendor "Suse" for product "Suse Linux" and version "9.0" | enterprise_server |
Affected
| ||||||
Suse Search vendor "Suse" | Suse Linux Search vendor "Suse" for product "Suse Linux" | 9.0 Search vendor "Suse" for product "Suse Linux" and version "9.0" | x86_64 |
Affected
| ||||||
Suse Search vendor "Suse" | Suse Linux Search vendor "Suse" for product "Suse Linux" | 9.1 Search vendor "Suse" for product "Suse Linux" and version "9.1" | - |
Affected
|