Back to Database
Status published
High
CVE-2005-0605
scan.c for LibXPM may allow attackers to execute arbitrary code...
Vulnerability Description
scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2005-0605
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.redhat.com/support/errata/RHSA-2005-331.html
- http://www.redhat.com/support/errata/RHSA-2005-412.html
- http://securitytracker.com/id?1013339
- http://secunia.com/advisories/18049
- ftp://patches.sgi.com/support/free/security/advisories/20060403-01-U
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.5/SCOSA-2006.5.txt
- http://bugs.gentoo.org/show_bug.cgi?id=83598
- http://www.gentoo.org/security/en/glsa/glsa-200503-15.xml
- http://www.debian.org/security/2005/dsa-723
- http://secunia.com/advisories/19624
- https://bugs.freedesktop.org/attachment.cgi?id=1909
- http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html
- http://secunia.com/advisories/18316
- http://secunia.com/advisories/14460
- http://www.redhat.com/support/errata/RHSA-2005-198.html
- http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00001.html
- http://www.redhat.com/support/errata/RHSA-2005-044.html
- http://security.gentoo.org/glsa/glsa-200503-08.xml
- http://www.securityfocus.com/bid/12714
- http://www.redhat.com/support/errata/RHSA-2008-0261.html
- http://bugs.gentoo.org/show_bug.cgi?id=83655
- http://www.redhat.com/support/errata/RHSA-2005-473.html
- http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.57/SCOSA-2005.57.txt
- https://usn.ubuntu.com/97-1/
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10411
- https://usn.ubuntu.com/92-1/
Affected Vendor
lesstif
View all reports →Affected Software
lesstif, propack, x11r6, alt linux, mandrake linux, mandrake linux corporate server, enterprise linux, enterprise linux desktop, fedora core, suse linux
Vulnerable Versions:
0.93.94, 3.0, 6.7.0, 6.8, 6.8.1, 3.3, 3.3.2, 3.3.3, 3.3.4, 3.3.5, 3.3.6, 4.0, 4.0.1, 4.0.2.11, 4.0.3, 4.1.0, 4.1.11, 4.1.12, 4.2.0, 4.2.1, 4.3.0, 4.3.0.1, 4.3.0.2, 2.3, 10.0, 10.1, 10.2, 2.1, core_2.0, core_3.0, 6.1, 6.2, 6.3, 6.4, 7.0, 7.1, 7.2, 7.3, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2
Timeline
Official Publish:
March 4th, 2005
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.