XLoadImage Multiple Remote Buffer Overflow Vulnerabilities
BID:15051
Info
XLoadImage Multiple Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 15051 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-3178 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 10 2005 12:00AM |
| Updated: | Mar 19 2015 08:46AM |
| Credit: | Discovery is credited to Ariel Berkman. |
| Vulnerable: |
xloadimage xloadimage 4.1 xli xli 1.17 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SGI Advanced Linux Environment 3.0 SCO Unixware 7.1.4 SCO Unixware 7.1.3 SCO Open Server 6.0 SCO Open Server 5.0.7 SCO Open Server 5.0.6 a SCO Open Server 5.0.6 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. Linux Desktop 1.0 RedHat Linux 9.0 i386 RedHat Linux 7.3 i386 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux WS 2.1 IA64 RedHat Enterprise Linux WS 2.1 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux ES 2.1 IA64 RedHat Enterprise Linux ES 2.1 RedHat Desktop 4.0 RedHat Desktop 3.0 RedHat Advanced Workstation for the Itanium Processor 2.1 IA64 RedHat Advanced Workstation for the Itanium Processor 2.1 Red Hat Fedora Core2 Red Hat Fedora Core1 Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux AS 2.1 IA64 Red Hat Enterprise Linux AS 2.1 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 2.1 x86_64 MandrakeSoft Corporate Server 2.1 Avaya Messaging Storage Server Avaya Message Networking Avaya Intuity LX Avaya CVLAN |
| Not Vulnerable: | |
Discussion
XLoadImage Multiple Remote Buffer Overflow Vulnerabilities
The xloadimage utility is affected by multiple remotely exploitable buffer-overflow vulnerabilities.
The problems present themselves when the application processes malformed image titles.
An attacker may exploit these issues to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access.
The xloadimage utility is affected by multiple remotely exploitable buffer-overflow vulnerabilities.
The problems present themselves when the application processes malformed image titles.
An attacker may exploit these issues to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access.
Exploit / POC
XLoadImage Multiple Remote Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
XLoadImage Multiple Remote Buffer Overflow Vulnerabilities
Solution:
Please see the referenced advisories for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
xli xli 1.17
xloadimage xloadimage 4.1
SCO Open Server 5.0.6
SCO Open Server 5.0.7
SCO Open Server 6.0
SCO Unixware 7.1.3
SCO Unixware 7.1.4
Solution:
Please see the referenced advisories for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
xli xli 1.17
-
Mandriva xli-1.17.0-4.1.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva xli-1.17.0-4.1.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/x86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva xli-1.17.0-4.2.C21mdk.i586.rpm
Corporate Server 2.1:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva xli-1.17.0-4.2.C21mdk.x86_64.rpm
Corporate Server 2.1/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva xli-1.17.0-8.1.101mdk.i586.rpm
Mandrake Linux 10.1
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva xli-1.17.0-8.1.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva xli-1.17.0-8.1.102mdk.i586.rpm
Mandrake Linux 10.2
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva xli-1.17.0-8.1.102mdk.x86_64.rpm
Mandrake Linux 10.2/x86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva xli-1.17.0-8.2.102mdk.i586.rpm
Mandrivalinux 10.2:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva xli-1.17.0-8.2.102mdk.x86_64.rpm
Mandrivalinux 10.2/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva xli-1.17.0-8.2.20060mdk.i586.rpm
Mandrivalinux 2006.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva xli-1.17.0-8.2.20060mdk.x86_64.rpm
Mandrivalinux 2006.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva xli-1.17.0-8.2.C30mdk.i586.rpm
Mandrake Corporate Server 3.0
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva xli-1.17.0-8.2.C30mdk.x86_64.rpm
Mandrake Corporate Server 3.0/x86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva xli-1.17.0-8.3.C30mdk.i586.rpm
Corporate 3.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva xli-1.17.0-8.3.C30mdk.x86_64.rpm
Corporate 3.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3
xloadimage xloadimage 4.1
-
RedHat xloadimage-4.1-21.2.legacy.i386.rpm
Red Hat Linux 7.3:
http://download.fedoralegacy.org/redhat/7.3/updates/i386/xloadimage-4. 1-21.2.legacy.i386.rpm -
RedHat xloadimage-4.1-27.2.legacy.i386.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/xloadimage-4.1- 27.2.legacy.i386.rpm -
RedHat xloadimage-4.1-29.2.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/xloadimage-4.1- 29.2.legacy.i386.rpm -
RedHat xloadimage-4.1-34.FC2.2.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/xloadimage-4.1- 34.FC2.2.legacy.i386.rpm
SCO Open Server 5.0.6
-
SCO p533253.507_vol.tar
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.62
SCO Open Server 5.0.7
-
SCO p533253.507_vol.tar
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.62
SCO Open Server 6.0
-
SCO p533253.600_vol.tar
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.62
SCO Unixware 7.1.3
-
SCO SCOSA-2005.56
UnixWare 7.1.3
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.56
SCO Unixware 7.1.4
-
SCO SCOSA-2005.56
UnixWare 7.1.3
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.56
References
XLoadImage Multiple Remote Buffer Overflow Vulnerabilities
References:
References: