PT-2004-3706 · Debian+1 · Lesstif-Doc+6
Chris Evans
·
Published
1970-01-01
·
Updated
2018-10-19
·
CVE-2004-0688
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
lesstif-dev (affected versions not specified)
lesstif-bin (affected versions not specified)
lesstif1 (affected versions not specified)
lesstif-dbg (affected versions not specified)
lesstif-doc (affected versions not specified)
libXpm versions prior to 6.8.1
Description
The issue involves multiple vulnerabilities in the lesstif package of the Debian GNU/Linux operating system, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, there are integer overflows in functions such as
xpmParseColors, XpmCreateImageFromXpmImage, CreateXImage, ParsePixels, and ParseAndPutPixels in libXpm before version 6.8.1, allowing remote attackers to execute arbitrary code via a malformed XPM image file.Recommendations
For lesstif-dev, update to a version that includes the fix for these vulnerabilities.
For lesstif-bin, update to a version that includes the fix for these vulnerabilities.
For lesstif1, update to a version that includes the fix for these vulnerabilities.
For lesstif-dbg, update to a version that includes the fix for these vulnerabilities.
For lesstif-doc, update to a version that includes the fix for these vulnerabilities.
For libXpm, update to version 6.8.1 or later to resolve the integer overflow issues in functions like
xpmParseColors and XpmCreateImageFromXpmImage.
At the moment, there is no information about a newer version that contains a fix for the lesstif package vulnerabilities.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hp-Ux
Lesstif-Bin
Lesstif-Dbg
Lesstif-Dev
Lesstif-Doc
Lesstif1
Libxpm