LWN.net Logo

xloadimage: missing input sanitizing, integer overflow

Package(s):xloadimage CVE #(s):CAN-2005-0638 CAN-2005-0639
Created:March 21, 2005 Updated:May 4, 2005
Description: Tavis Ormandy of the Gentoo Linux Security Audit Team has reported a flaw in the handling of compressed images, where shell meta-characters are not adequately escaped. CAN-2005-0638

Insufficient validation of image properties in have been discovered which could potentially result in buffer management errors. CAN-2005-0639

Alerts:
Mandriva MDKSA-2005:076 2005-04-20
Red Hat RHSA-2005:332-01 2005-04-19
Debian DSA-695-1 2005-03-21
Debian DSA-694-1 2005-03-21
Fedora FEDORA-2005-237 2005-03-18
Fedora FEDORA-2005-236 2005-03-18

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds