PT-2002-1052 · Unknown+2 · Imlib-Devel+3
Published
2002-03-15
·
Updated
2008-09-11
·
CVE-2002-0167
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
imlib versions prior to 1.9.13
imlib-cfgeditor versions prior to 1.9.13
imlib-devel versions prior to 1.9.13
Description
The issue affects the imlib package and its related components, potentially leading to a breach of confidentiality, integrity, and availability of protected information. Exploitation can be carried out remotely. The vulnerability may allow attackers to cause a denial of service or possibly execute arbitrary code via certain weaknesses in the NetPBM package, which is sometimes used by imlib to load trusted images.
Recommendations
For imlib versions prior to 1.9.13, update to version 1.9.13 or later to resolve the issue.
For imlib-cfgeditor versions prior to 1.9.13, update to version 1.9.13 or later to resolve the issue.
For imlib-devel versions prior to 1.9.13, update to version 1.9.13 or later to resolve the issue.
As a temporary workaround, consider restricting the use of the NetPBM package to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netpbm
Imlib
Imlib-Cfgeditor
Imlib-Devel