FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-1026

This CVE name corresponds to:

Entered Topic
2005-01-21 imlib -- xpm heap buffer overflows and integer overflows

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-1026
Phase Assigned(20041112)

Description

Multiple integer overflows in the image handler for imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.

References

Source Reference
DEBIAN DSA-628
GENTOO GLSA-200412-03
MANDRAKE MDKSA-2005:007
REDHAT RHSA-2004:651
BID 11830
OVAL oval:org.mitre.oval:def:10771