CVE-2004-0687

Publication date 20 October 2004

Last updated 24 July 2024


Ubuntu priority

Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm before 6.8.1 allow remote attackers to execute arbitrary code via a malformed XPM image file.

Status

Package Ubuntu Release Status
openmotif 7.04 feisty
Fixed 2.2.3-1.2ubuntu2
6.10 edgy
Fixed 2.2.3-1.2ubuntu2
6.06 LTS dapper
Fixed 2.2.3-1.2ubuntu2
xorg 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected

References

Related Ubuntu Security Notices (USN)

    • USN-27-1
    • libxpm4 vulnerability
    • 18 November 2004

Other references