CVE-2005-3178Improper Restriction of Operations within the Bounds of a Memory Buffer in Xloadimage

7 documents6 sources
Severity
5.1MEDIUMNVD
EPSS
2.3%
top 15.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 7
Latest updateMay 3

Description

Buffer overflow in xloadimage 4.1 and earlier, and xli, might allow user-assisted attackers to execute arbitrary code via a long title name in a NIFF file, which triggers the overflow during (1) zoom, (2) reduce, or (3) rotate operations.

CVSS vector

AV:N/AC:H/C:P/I:P/A:PExploitability: 4.9 | Impact: 6.4

Affected Packages5 packages

debiandebian/xloadimage< xli 1.17.0-20 (bookworm)
Debianxloadimage/xloadimage< 4.1-15+3
debiandebian/xli< xli 1.17.0-20 (bookworm)
Debianxli/xli< 1.17.0-20+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g3j8-jppq-c6p4: Buffer overflow in xloadimage 42022-05-03
OSV
CVE-2005-3178: Buffer overflow in xloadimage 42005-10-07

📋Vendor Advisories

2
Red Hat
security flaw2005-10-05
Debian
CVE-2005-3178: xli - Buffer overflow in xloadimage 4.1 and earlier, and xli, might allow user-assiste...2005

💬Community

1
Bugzilla
CVE-2005-3178 security flaw2018-08-16