CVE-2004-0802

5 documents5 sources
Severity
5.1MEDIUM
EPSS
6.3%
top 9.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 31
Latest updateApr 29

Description

Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817.

CVSS vector

AV:N/AC:H/C:P/I:P/A:PExploitability: 4.9 | Impact: 6.4

Affected Packages15 packages

Debianimlib2< 1.1.0-12.4+3
NVDenlightenment/imlib28 versions+7
NVDimagemagick/imagemagick10 versions+9
NVDconectiva/linux10.0, 9.0+1
NVDsuse/suse_linux6 versions+5

Also affects: Ubuntu Linux 4.1, Enterprise Linux 2.1, 3.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-pv68-cmw6-5544: Buffer overflow in the BMP loader in imlib2 before 12022-04-29
OSV
CVE-2004-0802: Buffer overflow in the BMP loader in imlib2 before 12004-12-31
CVEList
CVE-2004-0802: Buffer overflow in the BMP loader in imlib2 before 12004-09-24

📋Vendor Advisories

1
Debian
CVE-2004-0802: imlib2 - Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers...2004