CVE 2004-0914
Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive information, cause a denial of service (application crash), or execute arbitrary code via a certain XPM image file. NOTE: it is highly likely that this candidate will be SPLIT into other candidates in the future, per CVE's content decisions.
Related bugs and status
CVE-2004-0914 (Candidate) is related to these bugs:
Bug #245: CAN-2004-0914 not yet fixed in lesstif1
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
245 | CAN-2004-0914 not yet fixed in lesstif1 | lesstif1-1 (Ubuntu) | Medium | Fix Released |
Bug #7550: xserver-xfree86: obsolete configlets - need port to gtk2
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
7550 | xserver-xfree86: obsolete configlets - need port to gtk2 | xfree86 (Ubuntu) | Low | Invalid | ||
7550 | xserver-xfree86: obsolete configlets - need port to gtk2 | xfree86 (Debian) | Unknown | Fix Released |
Bug #7644: xfree86: FBTFS: wrong Build-Depends libstdc++-5-dev
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
7644 | xfree86: FBTFS: wrong Build-Depends libstdc++-5-dev | Ubuntu | High | Invalid | ||
7644 | xfree86: FBTFS: wrong Build-Depends libstdc++-5-dev | Debian | Unknown | Fix Released |
Bug #10271: xserver-xfree86: X crashes on load, UltraSPARC with 2.6.xx kernel and udev
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
10271 | xserver-xfree86: X crashes on load, UltraSPARC with 2.6.xx kernel and udev | xfree86 (Ubuntu) | High | Invalid | ||
10271 | xserver-xfree86: X crashes on load, UltraSPARC with 2.6.xx kernel and udev | xfree86 (Debian) | Unknown | Fix Released |
Bug #10973: xserver-xfree86: xserver (ATI or Radeon something 7500) crashes on variouslaunches of programcs from within X.
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
10973 | xserver-xfree86: xserver (ATI or Radeon something 7500) crashes on variouslaunches of programcs from within X. | xfree86 (Ubuntu) | High | Invalid | ||
10973 | xserver-xfree86: xserver (ATI or Radeon something 7500) crashes on variouslaunches of programcs from within X. | xfree86 (Debian) | Unknown | Fix Released |
Bug #12635: multiple security holes in XPM code (CAN-2004-0914)
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
12635 | multiple security holes in XPM code (CAN-2004-0914) | lesstif1-1 (Ubuntu) | High | Fix Released | ||
12635 | multiple security holes in XPM code (CAN-2004-0914) | lesstif1-1 (Debian) | Unknown | Fix Released |
Bug #13557: lesstif1-1: Further unfixed XPM buffer overflows (CAN-2005-0605)
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
13557 | lesstif1-1: Further unfixed XPM buffer overflows (CAN-2005-0605) | lesstif1-1 (Ubuntu) | High | Fix Released | ||
13557 | lesstif1-1: Further unfixed XPM buffer overflows (CAN-2005-0605) | lesstif1-1 (Debian) | Unknown | Fix Released |
Bug #13779: libxpm4: new buffer overflow security hole (CAN-2005-0605)
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
13779 | libxpm4: new buffer overflow security hole (CAN-2005-0605) | libxpm (Ubuntu) | High | Fix Released | ||
13779 | libxpm4: new buffer overflow security hole (CAN-2005-0605) | libxpm (Debian) | Unknown | Fix Released |
Bug #13903: libxpm4: new buffer overflow security hole (CAN-2005-0605)
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
13903 | libxpm4: new buffer overflow security hole (CAN-2005-0605) | libxpm (Ubuntu) | High | Fix Released | ||
13903 | libxpm4: new buffer overflow security hole (CAN-2005-0605) | libxpm (Debian) | Unknown | Fix Released |
Bug #1187507: (open)motif should properly transition from libmotif3
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1187507 | (open)motif should properly transition from libmotif3 | motif (Ubuntu) | Low | Fix Released | ||
1187507 | (open)motif should properly transition from libmotif3 | motif (Debian) | Unknown | Fix Released | ||
1187507 | (open)motif should properly transition from libmotif3 | openmotif (Ubuntu Precise) | Undecided | Fix Released | ||
1187507 | (open)motif should properly transition from libmotif3 | openmotif (Ubuntu Quantal) | Undecided | Fix Released | ||
1187507 | (open)motif should properly transition from libmotif3 | openmotif (Ubuntu Raring) | Undecided | Fix Released |
See the
CVE page on Mitre.org
for more details.