Updated packages are available to fix a vulnerability in WindowMaker. [Updated 16 April 2003] Added packages for Red Hat Linux on IBM iSeries and pSeries systems.
Window Maker is an X11 window manager which emulates the look and feel of the NeXTSTEP graphical user interface. Al Viro found a buffer overflow in Window Maker 0.80.0 and earlier which may allow remote attackers to execute arbitrary code via a certain image file that is not properly handled when Window Maker uses width and height information to allocate a buffer. This could be exploited for example by a user opening a malicious theme. Users of Window Maker are advised to upgrade to these erratum packages which contain a patch to correct this vulnerability.