Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2016-10164: [ANNOUNCE] libXpm 3.5.12

Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via (1) the number of extensions or (2) their concatenated length in a crafted XPM file, which triggers a heap-based buffer overflow.

CVE
#dos#git#buffer_overflow#auth

Matthieu Herrb matthieu at herrb.eu
Thu Dec 15 17:08:13 UTC 2016

  • Previous message: [ANNOUNCE] xf86-video-dummy 0.3.8
  • Next message: [ANNOUNCE] libXpm 3.5.12
  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

Jörg Sonnenberger (1): Fix abs() usage.

Matthieu Herrb (1): libXpm 3.5.12

Tobias Stoeckmann (4): Fix out out boundary read on unknown colors Gracefully handle EOF while parsing files. Avoid OOB write when handling malicious XPM files. Handle size_t in file/buffer length

git tag: libXpm-3.5.12

https://xorg.freedesktop.org/archive/individual/lib/libXpm-3.5.12.tar.bz2 MD5: 20f4627672edb2bd06a749f11aa97302 libXpm-3.5.12.tar.bz2 SHA1: 4e22fefe61714209539b08051b5287bcd9ecfd04 libXpm-3.5.12.tar.bz2 SHA256: fd6a6de3da48de8d1bb738ab6be4ad67f7cb0986c39bd3f7d51dd24f7854bdec libXpm-3.5.12.tar.bz2 PGP: https://xorg.freedesktop.org/archive/individual/lib/libXpm-3.5.12.tar.bz2.sig

https://xorg.freedesktop.org/archive/individual/lib/libXpm-3.5.12.tar.gz MD5: b286c884b11b5a0b4371175c5327141f libXpm-3.5.12.tar.gz SHA1: c837dfca61080a40031a3d9a83ea284acb619ab7 libXpm-3.5.12.tar.gz SHA256: 2523acc780eac01db5163267b36f5b94374bfb0de26fc0b5a7bee76649fd8501 libXpm-3.5.12.tar.gz PGP: https://xorg.freedesktop.org/archive/individual/lib/libXpm-3.5.12.tar.gz.sig

– Matthieu Herrb -------------- next part -------------- A non-text attachment was scrubbed… Name: signature.asc Type: application/pgp-signature Size: 811 bytes Desc: Digital signature URL: https://lists.x.org/archives/xorg/attachments/20161215/759dd232/attachment.sig\

  • Previous message: [ANNOUNCE] xf86-video-dummy 0.3.8
  • Next message: [ANNOUNCE] libXpm 3.5.12
  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

More information about the xorg mailing list

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda