NASLDB: RHSA-2005-332: xloadimage
General
ID: 18093
Name: RHSA-2005-332: xloadimage
Summary: Check for the version of the xloadimage packages
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS Base Vector: –
CVSS Temporal Vector: –
Port: 0
Family: Red Hat Local Security Checks
Type: Local
Description
A new xloadimage package that fixes bugs in handling malformed tiff
and pbm/pnm/ppm images, and in handling metacharacters in filenames is now
available.
This update has been rated as having low security impact by the
Red Hat Security Response Team.
The xloadimage utility displays images in an X Window System window,
loads images into the root window, or writes images into a file.
Xloadimage supports many image types (including GIF, TIFF, JPEG, XPM,
and XBM).
A flaw was discovered in xloadimage where filenames were not properly
quoted when calling the gunzip command. An attacker could create a file
with a carefully crafted filename so that it would execute arbitrary
commands if opened by a victim. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0638 to
this issue.
Another bug in xloadimage would cause it to crash if called with certain
invalid TIFF, PNM, PBM, or PPM file names.
All users of xloadimage should upgrade to this erratum package which
contains backported patches to correct these issues.
Exploiting
Exploit Available: –
Exploitability Ease: –
Sources
CVE: CVE-2005-0638
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: 2005/03/02
Patch Release: –
Plugin Release: 2005/04/19
Plugin
Version: 1.13
Filename: redhat-RHSA-2005-332.nasl
Filesize: 3107 bytes
MD5 Hash: 1d004aaa5fd23b38e8718f7301e2e5d7
Identification: Host/RedHat/rpm-list
Require Keys: Host/RedHat/rpm-list
Dependencies: "ssh_get_info.nasl"
Copyright: This script is Copyright© 2005-2011 Tenable Network Security, Inc.
- Latest Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













