Bug 63061 (CVE-2004-1026) - VUL-0: CVE-2004-1026: xpm crash bug in imlib
Summary: VUL-0: CVE-2004-1026: xpm crash bug in imlib
Status: RESOLVED FIXED
Alias: CVE-2004-1026
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: All Linux
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Marcus Meissner
QA Contact: Security Team bot
URL:
Whiteboard: CVE-2004-1026: CVSS v2 Base Score: 10...
Keywords:
Depends on:
Blocks:
 
Reported: 2004-11-09 18:19 UTC by Ludwig Nussel
Modified: 2021-10-16 08:55 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
crashing xpm (2.48 KB, text/plain)
2004-11-09 18:21 UTC, Ludwig Nussel
Details
patch (12.73 KB, text/plain)
2004-11-09 18:21 UTC, Ludwig Nussel
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Ludwig Nussel 2004-11-09 18:19:25 UTC
We received the following report via vendor-sec.
The issue is (semi?) public through redhat bugzilla.
Marcus I'll assign to you since you handled the last imlib case as
well.

Date: Tue, 9 Nov 2004 10:41:19 +0100 (MET)
From: Pavel Kankovsky <peak@argo.troja.mff.cuni.cz>
To: vendor-sec@lst.de
Subject: [vendor-sec] CAN-2004-0782-like vulnerability in Imlib 1.9

Imlib's XPM decoder is buggy. The attached XPM file kills it.

I made a jumbo patch for Fedora Legacy 7.3's Imlib 1.3.19 fixing this
and many other bugs (minus bugs already fixed by other patches such as 
patch for CAN-2004-0817) as well as introducing many preventive checks.
See the attached file. But remember, Imlib code is such a piece of
terrible mess (burn in hell, Rasterman!...sorry, I could not help...),
I might have missed something.

See also https://bugzilla.fedora.us/show_bug.cgi?id=2051#c11.

--Pavel Kankovsky aka Peak  [ Boycott Microsoft--http://www.vcnet.com/bms ]
"Resistance is futile. Open your source code and prepare for assimilation."
Comment 1 Ludwig Nussel 2004-11-09 18:21:01 UTC
Created attachment 25902 [details]
crashing xpm
Comment 2 Ludwig Nussel 2004-11-09 18:21:31 UTC
Created attachment 25903 [details]
patch
Comment 3 Marcus Meissner 2004-11-17 22:30:36 UTC
swamp id 24 
Comment 4 Thomas Biege 2004-12-01 18:00:51 UTC
packages approved 
Comment 5 Ludwig Nussel 2004-12-08 18:31:01 UTC
Gentoo says CAN-2004-1026 
Comment 6 Ludwig Nussel 2005-01-14 21:14:50 UTC
CAN-2004-1025 - heap overflows 
CAN-2004-1026 - integer overflows 
Comment 7 Thomas Biege 2009-10-13 19:59:09 UTC
CVE-2004-1026: CVSS v2 Base Score: 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)