PT-2004-3706 · Debian+1 · Lesstif-Doc+6

Chris Evans

·

Published

1970-01-01

·

Updated

2018-10-19

·

CVE-2004-0688

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions lesstif-dev (affected versions not specified) lesstif-bin (affected versions not specified) lesstif1 (affected versions not specified) lesstif-dbg (affected versions not specified) lesstif-doc (affected versions not specified) libXpm versions prior to 6.8.1
Description The issue involves multiple vulnerabilities in the lesstif package of the Debian GNU/Linux operating system, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, there are integer overflows in functions such as xpmParseColors, XpmCreateImageFromXpmImage, CreateXImage, ParsePixels, and ParseAndPutPixels in libXpm before version 6.8.1, allowing remote attackers to execute arbitrary code via a malformed XPM image file.
Recommendations For lesstif-dev, update to a version that includes the fix for these vulnerabilities. For lesstif-bin, update to a version that includes the fix for these vulnerabilities. For lesstif1, update to a version that includes the fix for these vulnerabilities. For lesstif-dbg, update to a version that includes the fix for these vulnerabilities. For lesstif-doc, update to a version that includes the fix for these vulnerabilities. For libXpm, update to version 6.8.1 or later to resolve the integer overflow issues in functions like xpmParseColors and XpmCreateImageFromXpmImage. At the moment, there is no information about a newer version that contains a fix for the lesstif package vulnerabilities.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03068
BDU:2015-03069
BDU:2015-03070
BDU:2015-03071
BDU:2015-03072
CVE-2004-0688
DSA-560-1
DSA-561-1
HPSBUX02119
RHSA-2004:478
RHSA-2004:537
RHSA-2008:0524

Affected Products

Hp-Ux
Lesstif-Bin
Lesstif-Dbg
Lesstif-Dev
Lesstif-Doc
Lesstif1
Libxpm