PT-2005-1079 · Libxpm+3 · Libxpm+3

Chris Gilbert

·

Published

2005-03-02

·

Updated

2018-10-03

·

CVE-2005-0605

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LibXPM (affected versions not specified) lesstif versions 0.93.15 lesstif-devel versions 0.93.15
Description The issue allows attackers to execute arbitrary code via a buffer overflow caused by a negative bitmap unit value in scan.c for LibXPM. For lesstif and lesstif-devel packages in Red Hat Enterprise Linux, exploitation can lead to disruption of confidentiality, integrity, and availability of protected information. The vulnerability can be exploited remotely.
Recommendations For LibXPM, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For lesstif version 0.93.15, update to a version that fixes the vulnerability. For lesstif-devel version 0.93.15, update to a version that fixes the vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07326
BDU:2015-07327
CVE-2005-0605
DSA-723-1
RHSA-2005:198
RHSA-2005:331
RHSA-2005:412
RHSA-2005_198
RHSA-2005_331
RHSA-2005_412
RHSA-2008:0261
RHSA-2008:0524

Affected Products

Libxpm
Red Hat
Lesstif
Lesstif-Dev