Name | CVE-2005-0605 |
Description | scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-723-1 |
Debian Bugs | 298183, 299236, 308819 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
lesstif2 | source | (unstable) | 1:0.93.94-11.1 | 298183, 299236 | ||
openmotif | source | (unstable) | 2.2.3-1.1 | medium | 308819 | |
xfree86 | source | woody | 4.1.0-16woody6 | DSA-723-1 | ||
xfree86 | source | (unstable) | 4.3.0.dfsg.1-13 | |||
xorg-x11 | source | (unstable) | (not affected) |
libxmp4 is the real culprit
- xorg-x11 <not-affected> (Fixed before upload into archive)
[sarge] - openmotif <no-dsa> (Non-free)