Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> SuSE Local Security Checks >> SUSE-SA:2004:034: XFree86-libs, xshared


Vulnerability Assessment Details

SUSE-SA:2004:034: XFree86-libs, xshared

Vulnerability Assessment Summary
Check for the version of the XFree86-libs, xshared package

Detailed Explanation for this Vulnerability Assessment

The remote host is missing the patch for the advisory SUSE-SA:2004:034 (XFree86-libs, xshared).


Chris Evans reported three vulnerabilities in libXpm which can
be exploited remotely by providing malformed XPM image files.
The function xpmParseColors() is vulnerable to an integer overflow
and a stack-based buffer overflow. The functions ParseAndPutPixels()
as well as ParsePixels() is vulnerable to a stack-based buffer overflow
too.
Additionally Matthieu Herrb found two one-byte buffer overflows.



Solution : http://www.suse.de/security/2004_34_xfree86_libs_xshared.html
Network Security Threat Level: High

Networks Security ID:

Vulnerability Assessment Copyright: This script is Copyright (C) 2004 Tenable Network Security

Cables, Connectors

Lot 50 HP EliteDesk 800 G1 SFF Chassis TESTED Motherboard/Power Supply Barebones
$1499.99
Lot 50 HP EliteDesk 800 G1 SFF Chassis TESTED Motherboard/Power Supply Barebones pictureHP ENVY DV7-7000 Series Motherboard with AMD A10-4600M 2.3GHz + 4 GB RAM
$40.0
HP ENVY DV7-7000 Series Motherboard with AMD A10-4600M 2.3GHz + 4 GB RAM  pictureASUS TUF Z390M-Pro Gaming Wi-Fi Z390 LGA-1151 9th Gen DDR4 mATX Motherboard
$102.0
ASUS TUF Z390M-Pro Gaming Wi-Fi Z390 LGA-1151 9th Gen DDR4 mATX Motherboard pictureFor Toshiba Satellite A350 laptop motherboard LA-4571P K000071720 DDR2 TEST OK
$66.99
For Toshiba Satellite A350 laptop motherboard LA-4571P K000071720 DDR2 TEST OK picture


Discussions

No Discussions have been posted on this vulnerability.