VDB

RHSA-2005%3A004

RHSA-2005%3A004 PUBLISHED CVSS 9.300000190734863 CRITICAL

Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm before 6.8.1 allow remote attackers to execute arbitrary code via a malformed XPM image file.

Risk Scores

CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Red HatRed Hat Linux Advanced Workstation 2.1
Red HatRed Hat Enterprise Linux AS (Advanced Server) version 2.1
Red HatRed Hat Enterprise Linux ES version 2.1
Red HatRed Hat Enterprise Linux WS version 2.1

Timeline

  • Jan 12, 2005 CVE Published
  • Nov 21, 2025 CVE Updated
  • Apr 24, 2026 Distribution Patch
  • Apr 24, 2026 Distribution Patch
  • Apr 24, 2026 Security Advisory
  • Apr 24, 2026 Security Advisory
  • Apr 24, 2026 Security Advisory
  • Apr 24, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›