Vulnerability Description
scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lesstif | Lesstif | 0.93.94 |
| Sgi | Propack | 3.0 |
| X.Org | X11R6 | 6.7.0 |
| Xfree86 Project | X11R6 | 3.3 |
| Altlinux | Alt Linux | 2.3 |
| Mandrakesoft | Mandrake Linux | 10.0 |
| Mandrakesoft | Mandrake Linux Corporate Server | 2.1 |
| Redhat | Enterprise Linux | 3.0 |
| Redhat | Enterprise Linux Desktop | 3.0 |
| Redhat | Fedora Core | core_2.0 |
| Suse | Suse Linux | 6.1 |
References
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.5/SCOSA-2006.5.txt
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.57/SCOSA-2005.57.txt
- ftp://patches.sgi.com/support/free/security/advisories/20060403-01-U
- http://bugs.gentoo.org/show_bug.cgi?id=83598PatchVendor Advisory
- http://bugs.gentoo.org/show_bug.cgi?id=83655PatchVendor Advisory
- http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html
- http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html
- http://secunia.com/advisories/14460
- http://secunia.com/advisories/18049
- http://secunia.com/advisories/18316
- http://secunia.com/advisories/19624
- http://security.gentoo.org/glsa/glsa-200503-08.xmlPatchVendor Advisory
- http://securitytracker.com/id?1013339PatchVendor Advisory
- http://www.debian.org/security/2005/dsa-723PatchVendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200503-15.xmlPatchVendor Advisory
FAQ
What is CVE-2005-0605?
CVE-2005-0605 is a vulnerability with a CVSS score of 7.5 (HIGH). scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.
How severe is CVE-2005-0605?
CVE-2005-0605 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-0605?
Check the references section above for vendor advisories and patch information. Affected products include: Lesstif Lesstif, Sgi Propack, X.Org X11R6, Xfree86 Project X11R6, Altlinux Alt Linux.