PT-2004-3706 · Debian+1 · Lesstif-Doc+6

Chris Evans

·

Publicado

1970-01-01

·

Atualizado

2018-10-19

·

CVE-2004-0688

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions lesstif-dev (affected versions not specified) lesstif-bin (affected versions not specified) lesstif1 (affected versions not specified) lesstif-dbg (affected versions not specified) lesstif-doc (affected versions not specified) libXpm versions prior to 6.8.1
Description The issue involves multiple vulnerabilities in the lesstif package of the Debian GNU/Linux operating system, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, there are integer overflows in functions such as xpmParseColors, XpmCreateImageFromXpmImage, CreateXImage, ParsePixels, and ParseAndPutPixels in libXpm before version 6.8.1, allowing remote attackers to execute arbitrary code via a malformed XPM image file.
Recommendations For lesstif-dev, update to a version that includes the fix for these vulnerabilities. For lesstif-bin, update to a version that includes the fix for these vulnerabilities. For lesstif1, update to a version that includes the fix for these vulnerabilities. For lesstif-dbg, update to a version that includes the fix for these vulnerabilities. For lesstif-doc, update to a version that includes the fix for these vulnerabilities. For libXpm, update to version 6.8.1 or later to resolve the integer overflow issues in functions like xpmParseColors and XpmCreateImageFromXpmImage. At the moment, there is no information about a newer version that contains a fix for the lesstif package vulnerabilities.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-03068
BDU:2015-03069
BDU:2015-03070
BDU:2015-03071
BDU:2015-03072
CVE-2004-0688
DSA-560-1
DSA-561-1
HPSBUX02119
RHSA-2004:478
RHSA-2004:537
RHSA-2008:0524

Produtos afetados

Hp-Ux
Lesstif-Bin
Lesstif-Dbg
Lesstif-Dev
Lesstif-Doc
Lesstif1
Libxpm