CVE-2004-0802: Buffer Overflow
Published Sep 24, 2004
·Updated
Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817.
Affected Software
73 affected components
Enlightenment Imlib=1.9
Enlightenment Imlib=1.9.1
Enlightenment Imlib=1.9.2
Enlightenment Imlib=1.9.3
Enlightenment Imlib=1.9.4
Enlightenment Imlib=1.9.5
Enlightenment Imlib=1.9.6
Enlightenment Imlib=1.9.7
Enlightenment Imlib=1.9.8
Enlightenment Imlib=1.9.9
Enlightenment Imlib=1.9.10
Enlightenment Imlib=1.9.11
Enlightenment Imlib=1.9.12
Enlightenment Imlib=1.9.13
Enlightenment Imlib=1.9.14
Enlightenment imlib2=1.0
Enlightenment imlib2=1.0.1
Enlightenment imlib2=1.0.2
Enlightenment imlib2=1.0.3
Enlightenment imlib2=1.0.4
Enlightenment imlib2=1.0.5
Enlightenment imlib2=1.1
Enlightenment imlib2=1.1.1
ImageMagick ImageMagick=5.3.3
ImageMagick ImageMagick=5.4.3
ImageMagick ImageMagick=5.4.4.5
ImageMagick ImageMagick=5.4.7
ImageMagick ImageMagick=5.4.8
ImageMagick ImageMagick=5.4.8.2.1.1.0
ImageMagick ImageMagick=5.5.3.2.1.2.0
ImageMagick ImageMagick=5.5.6.0_2003-04-09
ImageMagick ImageMagick=5.5.7
ImageMagick ImageMagick=6.0.2
Sun Java Desktop System=2.0
Sun Java Desktop System=2003
Conectiva Linux=9.0
Conectiva Linux=10.0
Mandrakesoft Mandrake Linux=9.2
Mandrakesoft Mandrake Linux=9.2
Mandrakesoft Mandrake Linux=10.0
Mandrakesoft Mandrake Linux=10.0
Mandrakesoft Mandrake Linux Corporate Server=2.1
Mandrakesoft Mandrake Linux Corporate Server=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=3.0
redhat Enterprise Linux=3.0
redhat Enterprise Linux=3.0
redhat Enterprise Linux Desktop=3.0
redhat Fedora Core=core_1.0
redhat Fedora Core=core_2.0
redhat Fedora Core=core_3.0
redhat Linux Advanced Workstation=2.1
redhat Linux Advanced Workstation=2.1
SUSE SuSE Linux=8.0
SUSE SuSE Linux=8.0
SUSE SuSE Linux=8.1
SUSE SuSE Linux=8.2
SUSE SuSE Linux=9.0
SUSE SuSE Linux=9.0
SUSE SuSE Linux=9.1
SUSE SuSE Linux=9.2
Turbolinux Turbolinux Desktop=10.0
Turbolinux Turbolinux Server=7.0
Turbolinux Turbolinux Server=8.0
Turbolinux Turbolinux Workstation=7.0
Turbolinux Turbolinux Workstation=8.0
Ubuntu Ubuntu Linux=4.1
Ubuntu Ubuntu Linux=4.1
Remediation
Patch Available
Patch Available
Event History
Sep 24, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0802?
CVE-2004-0802 is classified as a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2004-0802?
To fix CVE-2004-0802, you should update Imlib and ImageMagick to their latest versions.
3
What software is affected by CVE-2004-0802?
CVE-2004-0802 affects several versions of Imlib and ImageMagick, including Imlib2 versions before 1.1.2 and specific versions of Imlib and ImageMagick.
4
Can CVE-2004-0802 be exploited remotely?
Yes, CVE-2004-0802 can be exploited remotely through specially-crafted BMP images.
5
What type of vulnerability is CVE-2004-0802?
CVE-2004-0802 is a buffer overflow vulnerability that can lead to arbitrary code execution.