Rapid7 Vulnerability & Exploit Database

RHSA-2003:043: Updated WindowMaker packages fix vulnerability in theme-loading

Back to Search

RHSA-2003:043: Updated WindowMaker packages fix vulnerability in theme-loading

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
11/12/2002
Created
07/25/2018
Added
10/28/2005
Modified
07/04/2017

Description

Updated packages are available to fix a vulnerability in WindowMaker. [Updated 16 April 2003] Added packages for Red Hat Linux on IBM iSeries and pSeries systems.

Window Maker is an X11 window manager which emulates the look and feel of the NeXTSTEP graphical user interface. Al Viro found a buffer overflow in Window Maker 0.80.0 and earlier which may allow remote attackers to execute arbitrary code via a certain image file that is not properly handled when Window Maker uses width and height information to allocate a buffer. This could be exploited for example by a user opening a malicious theme. Users of Window Maker are advised to upgrade to these erratum packages which contain a patch to correct this vulnerability.

Solution(s)

  • redhat-upgrade-windowmaker
  • redhat-upgrade-windowmaker-libs

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;