Bug 135080 - CAN-2004-0687 buffer overflows in libXpm
CAN-2004-0687 buffer overflows in libXpm
Product: Fedora
Classification: Fedora
Component: lesstif (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Thomas Woerner
: Security
: 136981 (view as bug list)
Depends On:
Blocks: CVE-2004-0687
  Show dependency treegraph
Reported: 2004-10-08 10:59 EDT by Josh Bressers
Modified: 2008-01-28 11:01 EST (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2005-08-19 16:47:05 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Josh Bressers 2004-10-08 10:59:36 EDT
Multiple stack-based buffer overflows in (1) xpmParseColors in
parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in
parse.c for libXpm before 6.8.1 allow remote attackers to execute
arbitrary code via a malformed XPM image file.

This library itself is contained in lesstif.
Comment 1 Mark J. Cox (Product Security) 2004-10-27 06:04:15 EDT
*** Bug 136981 has been marked as a duplicate of this bug. ***
Comment 2 Marius Andreiana 2005-08-19 16:47:05 EDT
Thanks for the bug report. However, Red Hat no longer maintains this version of
the product. Please upgrade to the latest version and open a new bug if the problem

The Fedora Legacy project (http://fedoralegacy.org/) maintains some older releases, 
and if you believe this bug is interesting to them, please report the problem in
the bug tracker at: http://bugzilla.fedora.us/

lesstif is no longer included in FC4 or extras. Please report the problem
upstream if still present.

Note You need to log in before you can comment on or make changes to this bug.