Rapid7 Vulnerability & Exploit Database

CESA-2005:004: lesstif security update

Back to Search

CESA-2005:004: lesstif security update

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
01/10/2005
Created
07/25/2018
Added
03/12/2010
Modified
07/04/2017

Description

An updated lesstif package that fixes flaws in the Xpm library is now available for CentOS Linux 2.1.

LessTif provides libraries which implement the Motif industry standard graphical user interface. During a source code audit, Chris Evans discovered several stack overflow flaws and an integer overflow flaw in the libXpm library used to decode XPM (X PixMap) images. A vulnerable version of this library was found within Lesstif. An attacker could create a carefully crafted XPM file which would cause an application to crash or potentially execute arbitrary code if opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2004-0687,CAN-2004-0688, and CAN-2004-0914 to these issues. Users of LessTif are advised to upgrade to this erratum package, which contains backported security patches to the embedded libXpm library.

Solution(s)

  • centos-upgrade-lesstif
  • centos-upgrade-lesstif-devel

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;