Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malformed XPM image file.
2004-10-20T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | x.org | x11r6 | 6.7.0 | Yes |
Application | x.org | x11r6 | 6.8 | Yes |
Application | xfree86_project | x11r6 | 3.3.6 | Yes |
Application | xfree86_project | x11r6 | 4.0 | Yes |
Application | xfree86_project | x11r6 | 4.0.1 | Yes |
Application | xfree86_project | x11r6 | 4.0.2.11 | Yes |
Application | xfree86_project | x11r6 | 4.0.3 | Yes |
Application | xfree86_project | x11r6 | 4.1.0 | Yes |
Application | xfree86_project | x11r6 | 4.1.11 | Yes |
Application | xfree86_project | x11r6 | 4.1.12 | Yes |
Application | xfree86_project | x11r6 | 4.2.0 | Yes |
Application | xfree86_project | x11r6 | 4.2.1 | Yes |
Application | xfree86_project | x11r6 | 4.2.1 | Yes |
Application | xfree86_project | x11r6 | 4.3.0 | Yes |
Operating System | openbsd | openbsd | 3.4 | Yes |
Operating System | openbsd | openbsd | 3.5 | Yes |
Operating System | suse | suse_linux | 8 | Yes |
Operating System | suse | suse_linux | 8.1 | Yes |
Operating System | suse | suse_linux | 8.2 | Yes |
Operating System | suse | suse_linux | 9.0 | Yes |
Operating System | suse | suse_linux | 9.0 | Yes |
Operating System | suse | suse_linux | 9.0 | Yes |
Operating System | suse | suse_linux | 9.1 | Yes |