Debian Xli vulnerabilities

4 known vulnerabilities affecting debian/xli.

Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2005-0639HIGHCVSS 7.5fixed in xli 1.17.0-17 (bookworm)2005
CVE-2005-0639 [HIGH] CVE-2005-0639: xli - Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execut... Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via "buffer management errors" from certain image properties, some of which may be related to integer overflows in PPM files. Scope: local bookworm: resolved (fixed in 1.17.0-17) bullseye: resolved (fixed in 1.17.0-17) forky: resolved (fixed in 1.17.0-17) sid: resolved (fixed
debian
CVE-2005-0638HIGHCVSS 7.5fixed in xli 1.17.0-18 (bookworm)2005
CVE-2005-0638 [HIGH] CVE-2005-0638: xli - xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbit... xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command. Scope: local bookworm: resolved (fixed in 1.17.0-18) bullseye: resolved (fixed in 1.17.0-18) forky: resolved (fixed in 1.17.0-18) sid: resolved (fixed in 1.
debian
CVE-2005-3178MEDIUMCVSS 5.1fixed in xli 1.17.0-20 (bookworm)2005
CVE-2005-3178 [MEDIUM] CVE-2005-3178: xli - Buffer overflow in xloadimage 4.1 and earlier, and xli, might allow user-assiste... Buffer overflow in xloadimage 4.1 and earlier, and xli, might allow user-assisted attackers to execute arbitrary code via a long title name in a NIFF file, which triggers the overflow during (1) zoom, (2) reduce, or (3) rotate operations. Scope: local bookworm: resolved (fixed in 1.17.0-20) bullseye: resolved (fixed in 1.17.0-20) forky: resolved (fixed in 1.17.0-20) sid
debian
CVE-2001-0775HIGHCVSS 7.5PoCfixed in xli 1.17.0-17 (bookworm)2001
CVE-2001-0775 [HIGH] CVE-2001-0775: xli - Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote... Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attackers to execute arbitrary code via a FACES format image containing a long (1) Firstname or (2) Lastname field. Scope: local bookworm: resolved (fixed in 1.17.0-17) bullseye: resolved (fixed in 1.17.0-17) forky: resolved (fixed in 1.17.0-17) sid: resolved (fixed in 1.17.0-17) trixie: reso
debian