XPCD XPCD-SVGA Buffer Overflow Vulnerability
BID:10403
Info
XPCD XPCD-SVGA Buffer Overflow Vulnerability
| Bugtraq ID: | 10403 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0402 |
| Remote: | No |
| Local: | Yes |
| Published: | May 23 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Credited by Debian to "Jaguar". |
| Vulnerable: |
xpcd xpcd 2.0 8 Mandriva Linux Mandrake 10.0 AMD64 Mandriva Linux Mandrake 10.0 Mandriva Linux Mandrake 9.2 amd64 Mandriva Linux Mandrake 9.2 |
| Not Vulnerable: | |
Discussion
XPCD XPCD-SVGA Buffer Overflow Vulnerability
The xpcd-svga utility is susceptible to a locally exploitable buffer overflow condition. According to the report, xpcd-svga copies untrusted data into a buffer of predefined size without bounds checking. The procedure where this occurs is "pcd_open()", suggesting that the source of the data may be in the image file or photo disk.
The xpcd-svga utility is susceptible to a locally exploitable buffer overflow condition. According to the report, xpcd-svga copies untrusted data into a buffer of predefined size without bounds checking. The procedure where this occurs is "pcd_open()", suggesting that the source of the data may be in the image file or photo disk.
Exploit / POC
XPCD XPCD-SVGA Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
XPCD XPCD-SVGA Buffer Overflow Vulnerability
Solution:
Debian has issued an advisory (DSA 508-1) and fixes. See referenced advisory for more information.
Mandrakelinux has issued an advisory (MDKSA-2004:053) and fixes. See the referenced advisory for more information.
Mandriva Linux Mandrake 10.0
Mandriva Linux Mandrake 10.0 AMD64
Mandriva Linux Mandrake 9.2
Mandriva Linux Mandrake 9.2 amd64
Solution:
Debian has issued an advisory (DSA 508-1) and fixes. See referenced advisory for more information.
Mandrakelinux has issued an advisory (MDKSA-2004:053) and fixes. See the referenced advisory for more information.
Mandriva Linux Mandrake 10.0
-
Mandrake xpcd-2.08-20.1.100mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xpcd-gimp-2.08-20.1.100mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandriva Linux Mandrake 10.0 AMD64
-
Mandrake xpcd-2.08-20.1.100mdk.amd64.rpm
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xpcd-gimp-2.08-20.1.100mdk.amd64.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandriva Linux Mandrake 9.2
-
Mandrake xpcd-2.08-20.1.92mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xpcd-gimp-2.08-20.1.92mdk.amd64.rpm
http://www.mandrakesecure.net/en/ftp.php -
Mandrake xpcd-gimp-2.08-20.1.92mdk.i586.rpm
http://www.mandrakesecure.net/en/ftp.php
Mandriva Linux Mandrake 9.2 amd64
-
Mandrake xpcd-gimp-2.08-20.1.92mdk.amd64.rpm
http://www.mandrakesecure.net/en/ftp.php
References
XPCD XPCD-SVGA Buffer Overflow Vulnerability
References:
References: