Description
scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.
Affected products
- altlinux / alt_linux2.3 – 2.3
- altlinux / alt_linux2.3 – 2.3
- lesstif / lesstif0.93.94 – 0.93.94
- mandrakesoft / mandrake_linux10.0 – 10.0
- mandrakesoft / mandrake_linux10.0 – 10.0
- mandrakesoft / mandrake_linux10.1 – 10.1
- mandrakesoft / mandrake_linux10.1 – 10.1
- mandrakesoft / mandrake_linux10.2 – 10.2
- mandrakesoft / mandrake_linux10.2 – 10.2
- mandrakesoft / mandrake_linux_corporate_server3.0 – 3.0
- mandrakesoft / mandrake_linux_corporate_server3.0 – 3.0
- mandrakesoft / mandrake_linux_corporate_server2.1 – 2.1
- mandrakesoft / mandrake_linux_corporate_server2.1 – 2.1
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / enterprise_linux4.0 – 4.0
- RedHat / enterprise_linux4.0 – 4.0
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / enterprise_linux4.0 – 4.0
- RedHat / enterprise_linux_desktop3.0 – 3.0
- RedHat / enterprise_linux_desktop4.0 – 4.0
- RedHat / fedora_corecore_2.0 – core_2.0
- RedHat / fedora_corecore_3.0 – core_3.0
- sgi / propack3.0 – 3.0
- SUSE / suse_linux9.2 – 9.2
- SUSE / suse_linux7.0 – 7.0
- SUSE / suse_linux7.0 – 7.0
- SUSE / suse_linux7.1 – 7.1
- SUSE / suse_linux7.1 – 7.1
- SUSE / suse_linux7.1 – 7.1
- SUSE / suse_linux7.1 – 7.1
- SUSE / suse_linux7.1 – 7.1
- SUSE / suse_linux7.2 – 7.2
- SUSE / suse_linux7.2 – 7.2
- SUSE / suse_linux7.3 – 7.3
- SUSE / suse_linux7.3 – 7.3
- SUSE / suse_linux7.3 – 7.3
- SUSE / suse_linux7.3 – 7.3
- SUSE / suse_linux8.0 – 8.0
- SUSE / suse_linux8.0 – 8.0
- SUSE / suse_linux8.1 – 8.1
- SUSE / suse_linux8.2 – 8.2
- SUSE / suse_linux9.0 – 9.0
- SUSE / suse_linux9.0 – 9.0
- SUSE / suse_linux9.1 – 9.1
- SUSE / suse_linux9.1 – 9.1
- SUSE / suse_linux9.2 – 9.2
- SUSE / suse_linux6.1 – 6.1
- SUSE / suse_linux6.1 – 6.1
- SUSE / suse_linux6.2 – 6.2
- SUSE / suse_linux6.3 – 6.3
- SUSE / suse_linux6.3 – 6.3
- SUSE / suse_linux6.3 – 6.3
- SUSE / suse_linux6.4 – 6.4
- SUSE / suse_linux6.4 – 6.4
- SUSE / suse_linux6.4 – 6.4
- SUSE / suse_linux6.4 – 6.4
- SUSE / suse_linux7.0 – 7.0
- SUSE / suse_linux7.0 – 7.0
- SUSE / suse_linux7.0 – 7.0
- xfree86_project / x11r64.3.0.2 – 4.3.0.2
- xfree86_project / x11r64.3.0.1 – 4.3.0.1
- xfree86_project / x11r64.3.0 – 4.3.0
- xfree86_project / x11r64.2.1 – 4.2.1
- xfree86_project / x11r64.2.1 – 4.2.1
- xfree86_project / x11r64.2.0 – 4.2.0
- xfree86_project / x11r64.1.12 – 4.1.12
- xfree86_project / x11r64.1.11 – 4.1.11
- xfree86_project / x11r64.1.0 – 4.1.0
- xfree86_project / x11r64.0.3 – 4.0.3
- xfree86_project / x11r64.0.2.11 – 4.0.2.11
- xfree86_project / x11r64.0.1 – 4.0.1
- xfree86_project / x11r64.0 – 4.0
- xfree86_project / x11r63.3.6 – 3.3.6
- xfree86_project / x11r63.3.5 – 3.3.5
- xfree86_project / x11r63.3.4 – 3.3.4
- xfree86_project / x11r63.3.3 – 3.3.3
- xfree86_project / x11r63.3.2 – 3.3.2
- xfree86_project / x11r63.3 – 3.3
- X.Org / x11r66.8.1 – 6.8.1
- X.Org / x11r66.8 – 6.8
- X.Org / x11r66.7.0 – 6.7.0
References
- MISChttp://www.redhat.com/support/errata/RHSA-2005-331.html
- MISChttp://www.redhat.com/support/errata/RHSA-2005-412.html
- MISChttp://securitytracker.com/id?1013339
- VENDOR_ADVISORYhttp://secunia.com/advisories/18049
- VENDOR_ADVISORYftp://patches.sgi.com/support/free/security/advisories/20060403-01-U
- MISCftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.5/SCOSA-2006.5.txt
- MISChttp://bugs.gentoo.org/show_bug.cgi?id=83598
- MISChttp://www.gentoo.org/security/en/glsa/glsa-200503-15.xml
- VENDOR_ADVISORYhttp://www.debian.org/security/2005/dsa-723
- VENDOR_ADVISORYhttp://secunia.com/advisories/19624
- MISChttps://bugs.freedesktop.org/attachment.cgi?id=1909
- MAILING_LISThttp://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/18316
- VENDOR_ADVISORYhttp://secunia.com/advisories/14460
- MISChttp://www.redhat.com/support/errata/RHSA-2005-198.html
- MISChttp://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00001.html
- MISChttp://www.redhat.com/support/errata/RHSA-2005-044.html
- MISChttp://security.gentoo.org/glsa/glsa-200503-08.xml
- MISChttp://www.securityfocus.com/bid/12714
- MISChttp://www.redhat.com/support/errata/RHSA-2008-0261.html
- MISChttp://bugs.gentoo.org/show_bug.cgi?id=83655
- MISChttp://www.redhat.com/support/errata/RHSA-2005-473.html
- MAILING_LISThttp://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html
- MISCftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.57/SCOSA-2005.57.txt
- VENDOR_ADVISORYhttps://usn.ubuntu.com/97-1/
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10411
- VENDOR_ADVISORYhttps://usn.ubuntu.com/92-1/