PT-2002-1052 · Unknown+2 · Imlib-Devel+3
Publicado
2002-03-15
·
Atualizado
2008-09-11
·
CVE-2002-0167
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
imlib versions prior to 1.9.13
imlib-cfgeditor versions prior to 1.9.13
imlib-devel versions prior to 1.9.13
Description
The issue affects the imlib package and its related components, potentially leading to a breach of confidentiality, integrity, and availability of protected information. Exploitation can be carried out remotely. The vulnerability may allow attackers to cause a denial of service or possibly execute arbitrary code via certain weaknesses in the NetPBM package, which is sometimes used by imlib to load trusted images.
Recommendations
For imlib versions prior to 1.9.13, update to version 1.9.13 or later to resolve the issue.
For imlib-cfgeditor versions prior to 1.9.13, update to version 1.9.13 or later to resolve the issue.
For imlib-devel versions prior to 1.9.13, update to version 1.9.13 or later to resolve the issue.
As a temporary workaround, consider restricting the use of the NetPBM package to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Netpbm
Imlib
Imlib-Cfgeditor
Imlib-Devel