Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Mandrake Local Security Checks >> MDKSA-2004:124: xorg-x11


Vulnerability Assessment Details

MDKSA-2004:124: xorg-x11

Vulnerability Assessment Summary
Check for the version of the xorg-x11 package

Detailed Explanation for this Vulnerability Assessment

The remote host is missing the patch for the advisory MDKSA-2004:124 (xorg-x11).



Chris Evans found several stack and integer overflows in the libXpm code of
X.Org/XFree86:

Stack overflows (CVE-2004-0687):

Careless use of strcat() in both the XPMv1 and XPMv2/3 xpmParseColors code
leads to a stack based overflow (parse.c).

Stack overflow reading pixel values in ParseAndPutPixels (create.c) as well as
ParsePixels (parse.c).

Integer Overflows (CVE-2004-0688):

Integer overflow allocating colorTable in xpmParseColors (parse.c) - probably a
crashable but not exploitable offence.

Additionally, the xorg-x11 packages have been patched with a backport from cvs
to resolve a failure running the lsb-test-vsw4 test suite, which will soon be
required for LSB2.0 compliance.

The updated packages have patches from Chris Evans and Matthieu Herrb to
address these vulnerabilities.



Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2004:124
Network Security Threat Level: High

Networks Security ID:

Vulnerability Assessment Copyright: This script is Copyright (C) 2004 Tenable Network Security

Cables, Connectors


For Lenovo IdeaPad 3 15IIL05 15IML05 15ADA05 15ARE05 Palmrest Keyboard Touchpad picture

For Lenovo IdeaPad 3 15IIL05 15IML05 15ADA05 15ARE05 Palmrest Keyboard Touchpad

$59.25



LCD Back Cover for Lenovo Ideapad Flex 5-14IIL05 14ARE05 14ITL05 14ALC05 picture

LCD Back Cover for Lenovo Ideapad Flex 5-14IIL05 14ARE05 14ITL05 14ALC05

$68.99



NEW Palmrest Keyboard For Lenovo Thinkpad E15 Gen 2 20T8 20T9 Black 5M10W64513 picture

NEW Palmrest Keyboard For Lenovo Thinkpad E15 Gen 2 20T8 20T9 Black 5M10W64513

$80.99



Lenovo IP 5 16IAU7 16

Lenovo IP 5 16IAU7 16" 2.5K Chromebook i3-1215U 8GB Ram 128GB eMMC Chrome OS

$219.99



Lenovo ThinkPad T480s 14

Lenovo ThinkPad T480s 14" Touch Core i5-8350U 1.70GHZ 16GB RAM 256GB SSD Win 11

$159.00



Notebook Lenovo Slim Pro 9 Laptop, 16

Notebook Lenovo Slim Pro 9 Laptop, 16" Glass, i9-13905H, 32GB, 1TB SSD

$1023.99



Lenovo Ideapad 1i 15.6

Lenovo Ideapad 1i 15.6" FHD Notebook Intel Core i5-1235U 8GB RAM 256GB SSD

$339.99



Lenovo Loq 15Irh8 15

Lenovo Loq 15Irh8 15" Laptop Core i5-13420H GeForce RTX 2050 16GB 512GB SSD W11H

$529.99



Lenovo ThinkPad L15 15.6” FHD Laptop AMD Ryzen 5 16GB RAM 512GB SSD Windows 10 picture

Lenovo ThinkPad L15 15.6” FHD Laptop AMD Ryzen 5 16GB RAM 512GB SSD Windows 10

$239.99



Lenovo Notebook IdeaPad 1 Laptop, N6000, 4GB, 128GB eMMC, Win 11 Home-Certified picture

Lenovo Notebook IdeaPad 1 Laptop, N6000, 4GB, 128GB eMMC, Win 11 Home-Certified

$229.49



Discussions

No Discussions have been posted on this vulnerability.