Buffer overflow in xloadimage 4.1 and earlier, and xli, might allow user-assisted attackers to execute arbitrary code via a long title name in a NIFF file, which triggers the overflow during (1) zoom, (2) reduce, or (3) rotate operations.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Xli | Xli | * | * |
| Xloadimage | Xloadimage | * | 4.1 (including) |
| Red Hat Enterprise Linux 3 | RedHat | xloadimage-0:4.1-36.RHEL3 | * |
| Red Hat Enterprise Linux 4 | RedHat | xloadimage-0:4.1-36.RHEL4 | * |
| Xli | Ubuntu | dapper | * |
| Xli | Ubuntu | devel | * |
| Xli | Ubuntu | edgy | * |
| Xli | Ubuntu | feisty | * |