CVE-2008-5187
published 2008-11-21CVE-2008-5187: The load function in the XPM loader for imlib2 1.4.2, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.64%
88.3th percentile
The load function in the XPM loader for imlib2 1.4.2, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XPM file that triggers a "pointer arithmetic error" and a heap-based buffer overflow, a different vulnerability than CVE-2008-2426.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imlib2 | < imlib2 1.4.0-1.2 (bookworm) | imlib2 1.4.0-1.2 (bookworm) |
| enlightenment | imlib2 | — | — |
| enlightenment | imlib2 | >= 0 < 1.4.0-1.2 | 1.4.0-1.2 |
| enlightenment | imlib2 | >= 0 < 1.4.0-1.2 | 1.4.0-1.2 |
| enlightenment | imlib2 | >= 0 < 1.4.0-1.2 | 1.4.0-1.2 |
| enlightenment | imlib2 | >= 0 < 1.4.0-1.2 | 1.4.0-1.2 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Imlib2 vulnerability
vendor_ubuntu·2008-12-02
CVE-2008-5187 Imlib2 vulnerability
Title: Imlib2 vulnerability
Summary: Imlib2 vulnerability
It was discovered that Imlib2 did not correctly handle certain malformed
XPM images. If a user were tricked into opening a specially crafted image
with an application that uses Imlib2, an attacker could cause a denial of
service and possibly execute arbitrary code with the user's privileges.
Instructions: After a standard system upgrade you need to restart any applications that
use Imlib2 to effect the necessary changes.
Red Hat
imilb2: pointer arithmetic flaw in XPM loader
vendor_redhat·2008-11-14·CVSS 9.3
CVE-2008-5187 [CRITICAL] imilb2: pointer arithmetic flaw in XPM loader
imilb2: pointer arithmetic flaw in XPM loader
The load function in the XPM loader for imlib2 1.4.2, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XPM file that triggers a "pointer arithmetic error" and a heap-based buffer overflow, a different vulnerability than CVE-2008-2426.
Statement: Not vulnerable. This issue does not affect the versions of imlib as shipped with Red Hat Enterprise Linux 2.1, 3, or 4.
Debian
CVE-2008-5187: imlib2 - The load function in the XPM loader for imlib2 1.4.2, and possibly other version...
vendor_debian·2008·CVSS 9.3
CVE-2008-5187 [CRITICAL] CVE-2008-5187: imlib2 - The load function in the XPM loader for imlib2 1.4.2, and possibly other version...
The load function in the XPM loader for imlib2 1.4.2, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XPM file that triggers a "pointer arithmetic error" and a heap-based buffer overflow, a different vulnerability than CVE-2008-2426.
Scope: local
bookworm: resolved (fixed in 1.4.0-1.2)
bullseye: resolved (fixed in 1.4.0-1.2)
forky: resolved (fixed in 1.4.0-1.2)
sid: resolved (fixed in 1.4.0-1.2)
trixie: resolved (fixed in 1.4.0-1.2)
GHSA
GHSA-793h-w8mx-wf86: The load function in the XPM loader for imlib2 1
ghsa_unreviewed·2022-05-17·CVSS 9.3
CVE-2008-5187 [CRITICAL] CWE-119 GHSA-793h-w8mx-wf86: The load function in the XPM loader for imlib2 1
The load function in the XPM loader for imlib2 1.4.2, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XPM file that triggers a "pointer arithmetic error" and a heap-based buffer overflow, a different vulnerability than CVE-2008-2426.
OSV
CVE-2008-5187: The load function in the XPM loader for imlib2 1
osv·2008-11-21·CVSS 9.3
CVE-2008-5187 [CRITICAL] CVE-2008-5187: The load function in the XPM loader for imlib2 1
The load function in the XPM loader for imlib2 1.4.2, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XPM file that triggers a "pointer arithmetic error" and a heap-based buffer overflow, a different vulnerability than CVE-2008-2426.
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=505714#15http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.htmlhttp://osvdb.org/49970http://secunia.com/advisories/32796http://secunia.com/advisories/32843http://secunia.com/advisories/32949http://secunia.com/advisories/32963http://secunia.com/advisories/33323http://secunia.com/advisories/33568http://security.gentoo.org/glsa/glsa-200812-23.xmlhttp://www.debian.org/security/2008/dsa-1672http://www.mandriva.com/security/advisories?name=MDVSA-2009:019http://www.openwall.com/lists/oss-security/2008/11/20/5http://www.securityfocus.com/bid/32371http://www.ubuntu.com/usn/USN-683-1http://www.vupen.com/english/advisories/2008/3212https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00856.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-November/msg00858.htmlhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=505714#15http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.htmlhttp://osvdb.org/49970http://secunia.com/advisories/32796http://secunia.com/advisories/32843http://secunia.com/advisories/32949http://secunia.com/advisories/32963http://secunia.com/advisories/33323http://secunia.com/advisories/33568http://security.gentoo.org/glsa/glsa-200812-23.xmlhttp://www.debian.org/security/2008/dsa-1672http://www.mandriva.com/security/advisories?name=MDVSA-2009:019http://www.openwall.com/lists/oss-security/2008/11/20/5http://www.securityfocus.com/bid/32371http://www.ubuntu.com/usn/USN-683-1http://www.vupen.com/english/advisories/2008/3212https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00856.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-November/msg00858.html
2008-11-21
Published