LWN.net Logo

xpcd: buffer overflow

Package(s):xpcd CVE #(s):CAN-2004-0402
Created:May 24, 2004 Updated:June 1, 2004
Description: Jaguar discovered a vulnerability in one component of xpcd, a PhotoCD viewer. xpcd-svga, part of xpcd which uses svgalib to display graphics on the console, would copy user-supplied data of arbitrary length into a fixed-size buffer in the pcd_open function.
Alerts:
Mandrake MDKSA-2004:053 2004-06-01
Debian DSA-508-1 2004-05-22

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds