CVE-2004-0914: Integer Overflow
Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive information, cause a denial of service (application crash), or execute arbitrary code via a certain XPM image file. NOTE: it is highly likely that this candidate will be SPLIT into other candidates in the future, per CVE's content decisions.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0914?
CVE-2004-0914 has been classified as a moderate severity vulnerability due to its potential for remote code execution and Denial of Service.
How do I fix CVE-2004-0914?
To fix CVE-2004-0914, upgrade to the patched version of the affected software as recommended by your software vendor.
What software is affected by CVE-2004-0914?
CVE-2004-0914 affects multiple versions of libXpm as used in XFree86 and other related packages, specifically versions 6.8.1 and earlier.
What types of vulnerabilities are included in CVE-2004-0914?
CVE-2004-0914 includes multiple vulnerabilities such as integer overflows, out-of-bounds memory accesses, directory traversal, and endless loops.
Can CVE-2004-0914 be exploited remotely?
Yes, CVE-2004-0914 can be exploited remotely by attackers to potentially execute arbitrary code or cause a Denial of Service.