CVE-2004-0687Improper Restriction of Operations within the Bounds of a Memory Buffer in Openbsd

12 documents6 sources
Severity
7.5HIGHNVD
EPSS
22.1%
top 4.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 20
Latest updateApr 29

Description

Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm before 6.8.1 allow remote attackers to execute arbitrary code via a malformed XPM image file.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages4 packages

NVDx.org/x11r66.7.0, 6.8+1
NVDopenbsd/openbsd3.4, 3.5+1
NVDsuse/suse_linux5 versions+4
NVDxfree86_project/x11r611 versions+10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3r6w-5wg8-cf38: Multiple stack-based buffer overflows in (1) xpmParseColors in parse2022-04-29
CVEList
CVE-2004-0687: Multiple stack-based buffer overflows in (1) xpmParseColors in parse2004-09-24

📋Vendor Advisories

3
Ubuntu
libxpm4 vulnerability2004-11-18
Red Hat
openmotif21 stack overflows in libxpm2004-10-07
Red Hat
security flaw2004-09-15

💬Community

4
Bugzilla
CVE-2004-0782 security flaw2018-08-16
Bugzilla
CVE-2004-0687 openmotif21 stack overflows in libxpm2008-01-28
Bugzilla
CVE-2004-0688 openmotif21 stack overflows in libxpm2008-01-28
Bugzilla
CAN-2004-0687 libxpm flaws affect OpenMotif (CAN-2004-0688, CAN-2004-0914)2004-10-05
CVE-2004-0687 — Openbsd vulnerability | cvebase