HIGH
security flaw
Published Sep 17, 2004
7.5
HIGHCVSS 2.0
EPSS 9.43%
Description
Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).
Affected products
No data.
No data.
Red Hat Enterprise Linux 3
gdk-pixbuf-1:0.22.0-11.3.3
Fixed · RHSA-2004:447
Red Hat Enterprise Linux 3
gtk2-0:2.2.4-8.1
Fixed · RHSA-2004:466
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | gdk-pixbuf-1:0.22.0-11.3.3 | Fixed | RHSA-2004:447 |
| Red Hat Enterprise Linux 3 | gtk2-0:2.2.4-8.1 | Fixed | RHSA-2004:466 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (22)
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000875 vendor-advisoryx_refsource_CONECTIVAThird Party Advisory
- http://marc.info/?l=bugtraq&m=109528994916275&w=2 mailing-listx_refsource_BUGTRAQThird Party Advisory
- http://scary.beasts.org/security/CESA-2004-005.txt x_refsource_MISCThird Party Advisory
- http://secunia.com/advisories/17657 third-party-advisoryx_refsource_SECUNIABroken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101776-1 vendor-advisoryx_refsource_SUNALERTThird Party Advisory
- http://www.kb.cert.org/vuls/id/369358 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:095 vendor-advisoryx_refsource_MANDRAKEThird Party Advisory
- http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096 vendor-advisoryx_refsource_MANDRAKEThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:214 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.redhat.com/support/errata/RHSA-2004-447.html vendor-advisoryx_refsource_REDHATPatchVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2004-466.html vendor-advisoryx_refsource_REDHATPatchVendor Advisory
- http://www.securityfocus.com/archive/1/419771/100/0/threaded vendor-advisoryx_refsource_FEDORAThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/11195 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2004-0783 Vendor Advisory
- https://bugzilla.fedora.us/show_bug.cgi?id=2005 vendor-advisoryx_refsource_FEDORAIssue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=1617284 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-0781 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17385 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2004-0783
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1786 vdb-entrysignaturex_refsource_OVALBroken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9348 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cve.org/CVERecord?id=CVE-2004-0783
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 17, 2004
Updated Aug 8, 2024
Reserved Aug 17, 2004
Link CVE-2004-0783
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2004-0781 Assigner mitre
Published Sep 17, 2004
Updated Aug 8, 2024
Exploited since n/a
Link EUVD-2004-0781