HIGH · 10.0

CVE-2004-0914

Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4)...

Vulnerability Description

Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive information, cause a denial of service (application crash), or execute arbitrary code via a certain XPM image file. NOTE: it is highly likely that this candidate will be SPLIT into other candidates in the future, per CVE's content decisions.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
LesstifLesstif0.93
X.OrgX11R66.7.0
Xfree86 ProjectX11R63.3
GentooLinuxAll versions
RedhatFedora Corecore_2.0
SuseSuse Linux1.0

References

FAQ

What is CVE-2004-0914?

CVE-2004-0914 is a vulnerability with a CVSS score of 10.0 (HIGH). Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4)...

How severe is CVE-2004-0914?

CVE-2004-0914 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0914?

Check the references section above for vendor advisories and patch information. Affected products include: Lesstif Lesstif, X.Org X11R6, Xfree86 Project X11R6, Gentoo Linux, Redhat Fedora Core.