CVE Vulnerabilities

CVE-2004-0688

Published: Oct 20, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malformed XPM image file.

Affected Software

NameVendorStart VersionEnd Version
X11r6X.org6.7.0 (including)6.7.0 (including)
X11r6X.org6.8 (including)6.8 (including)
X11r6Xfree86_project3.3.6 (including)3.3.6 (including)
X11r6Xfree86_project4.0 (including)4.0 (including)
X11r6Xfree86_project4.0.1 (including)4.0.1 (including)
X11r6Xfree86_project4.0.2.11 (including)4.0.2.11 (including)
X11r6Xfree86_project4.0.3 (including)4.0.3 (including)
X11r6Xfree86_project4.1.0 (including)4.1.0 (including)
X11r6Xfree86_project4.1.11 (including)4.1.11 (including)
X11r6Xfree86_project4.1.12 (including)4.1.12 (including)
X11r6Xfree86_project4.2.0 (including)4.2.0 (including)
X11r6Xfree86_project4.2.1 (including)4.2.1 (including)
X11r6Xfree86_project4.3.0 (including)4.3.0 (including)
Red Hat Enterprise Linux 3RedHatXFree86-0:4.3.0-69.EL*
Red Hat Enterprise Linux 3RedHatopenmotif-0:2.2.3-4.RHEL3.4*
Red Hat Enterprise Linux 3RedHatopenmotif21-0:2.1.30-9.RHEL3.4*
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Enterprise Linux ES version 2.1RedHat*
Red Hat Enterprise Linux ES version 2.1RedHat*
Red Hat Enterprise Linux WS version 2.1RedHat*
Red Hat Enterprise Linux WS version 2.1RedHat*
Red Hat Linux Advanced Workstation 2.1RedHat*
Red Hat Linux Advanced Workstation 2.1RedHat*
Red Hat Network Satellite Server v 4.2RedHatjabberd-0:2.0s10-3.38.rhn*
Red Hat Network Satellite Server v 4.2RedHatjava-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4*
Red Hat Network Satellite Server v 4.2RedHatjfreechart-0:0.9.20-3.rhn*
Red Hat Network Satellite Server v 4.2RedHatopenmotif21-0:2.1.30-11.RHEL4.6*
Red Hat Network Satellite Server v 4.2RedHatperl-Crypt-CBC-0:2.24-1.el4*
Red Hat Network Satellite Server v 4.2RedHatrhn-apache-0:1.3.27-36.rhn.rhel4*
Red Hat Network Satellite Server v 4.2RedHatrhn-modjk-0:1.2.23-2rhn.rhel4*
Red Hat Network Satellite Server v 4.2RedHatrhn-modperl-0:1.29-16.rhel4*
Red Hat Network Satellite Server v 4.2RedHatrhn-modssl-0:2.8.12-8.rhn.10.rhel4*
Red Hat Network Satellite Server v 4.2RedHattomcat5-0:5.0.30-0jpp_10rh*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatjabberd-0:2.0s10-3.37.rhn*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatjava-1.4.2-ibm-0:1.4.2.10-1jpp.2.el3*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatjfreechart-0:0.9.20-3.rhn*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatopenmotif21-0:2.1.30-9.RHEL3.8*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatperl-Crypt-CBC-0:2.24-1.el3*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatrhn-apache-0:1.3.27-36.rhn.rhel3*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatrhn-modjk-0:1.2.23-2rhn.rhel3*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatrhn-modperl-0:1.29-16.rhel3*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatrhn-modssl-0:2.8.12-8.rhn.10.rhel3*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHattomcat5-0:5.0.30-0jpp_10rh*
Lesstif1-1Ubuntudapper*
Lesstif1-1Ubuntuedgy*
Lesstif2Ubuntudapper*
Lesstif2Ubuntudevel*
Lesstif2Ubuntuedgy*
Lesstif2Ubuntufeisty*
OpenmotifUbuntudapper*
OpenmotifUbuntudevel*
OpenmotifUbuntuedgy*
OpenmotifUbuntufeisty*

References