PT-2002-1052 · Unknown+2 · Imlib-Devel+3

Published

2002-03-15

·

Updated

2008-09-11

·

CVE-2002-0167

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions imlib versions prior to 1.9.13 imlib-cfgeditor versions prior to 1.9.13 imlib-devel versions prior to 1.9.13
Description The issue affects the imlib package and its related components, potentially leading to a breach of confidentiality, integrity, and availability of protected information. Exploitation can be carried out remotely. The vulnerability may allow attackers to cause a denial of service or possibly execute arbitrary code via certain weaknesses in the NetPBM package, which is sometimes used by imlib to load trusted images.
Recommendations For imlib versions prior to 1.9.13, update to version 1.9.13 or later to resolve the issue. For imlib-cfgeditor versions prior to 1.9.13, update to version 1.9.13 or later to resolve the issue. For imlib-devel versions prior to 1.9.13, update to version 1.9.13 or later to resolve the issue. As a temporary workaround, consider restricting the use of the NetPBM package to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-08016
BDU:2015-08017
BDU:2015-08018
CVE-2002-0167

Affected Products

Netpbm
Imlib
Imlib-Cfgeditor
Imlib-Devel