VulnerabilityModified
CVE-2005-0639
Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via "buffer management errors" from certain image properties, some of which may be related to integer overflows in PPM files.
HIGH 7.5EPSS 2.82%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.82%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via "buffer management errors" from certain image properties, some of which may be related to integer overflows in PPM files.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.82% probability · 86th percentile
- CISA KEV
- Not listed
- Affected
- xli/xli · altlinux/alt linux · suse/suse linux
- Source
- cve@mitre.org
References
- http://bugs.gentoo.org/show_bug.cgi?id=79762Vendor Advisory
- http://secunia.com/advisories/14459Patch, Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200503-05.xmlVendor Advisory
- http://www.debian.org/security/2005/dsa-695Vendor Advisory
- http://bugs.gentoo.org/show_bug.cgi?id=79762Vendor Advisory
- http://secunia.com/advisories/14459Patch, Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200503-05.xmlVendor Advisory
- http://www.debian.org/security/2005/dsa-695Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.