Buffer overflow in xloadimage 4.1 and earlier, and xli, might allow user-assisted attackers to execute arbitrary code via a long title name in a NIFF file, which triggers the overflow during (1) zoom, (2) reduce, or (3) rotate operations.
CVSS Details
- CVSS 3.1 Base Score: 5.6
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xliUpgrade xloadimage | Jul 30, 2024 | Oct 7, 2005 |
| Freebsd | — | Upgrade xliUpgrade xloadimage | Dec 10, 2025 | Oct 20, 2005 |
| Gentoo Linux | — | Upgrade media-gfx/xli.Upgrade media-gfx/xloadimage. | Oct 30, 2017 | Oct 7, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub