PT-2002-3164 · Unknown · Windowmaker+1

Published

1970-01-01

·

Updated

2008-09-05

·

CVE-2002-1277

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Window Maker versions 0.80.0 and earlier WindowMaker version 0.64.0 WindowMaker version 0.61.1 WindowMaker-libs version 0.64.0
Description The issue is related to a buffer overflow in Window Maker that may allow remote attackers to execute arbitrary code via a certain image file. This can lead to a disruption of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be done remotely.
Recommendations For Window Maker versions 0.80.0 and earlier, consider updating to a newer version to mitigate the risk. For WindowMaker version 0.64.0, restrict access to the vulnerable module to minimize the risk of exploitation. For WindowMaker version 0.61.1, avoid using the vulnerable function until a patch is available. For WindowMaker-libs version 0.64.0, disable the vulnerable library until a fix is provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability in libwraster2 and libwraster2-dev packages.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-02939
BDU:2015-02940
BDU:2015-07918
BDU:2015-07919
BDU:2015-07920
CVE-2002-1277
DSA-190

Affected Products

Windowmaker
Windowmaker-Libs