CVE-2005-0605: Buffer Overflow
Published Mar 2, 2005
·Updated
scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmapunit value that leads to a buffer overflow.
Affected Software
82 affected components
LessTif LessTif=0.93.94
SGI ProPack=3.0
X.Org X11R6=6.7.0
X.Org X11R6=6.8
X.Org X11R6=6.8.1
Xfree86 Project X11r6=3.3
Xfree86 Project X11r6=3.3.2
Xfree86 Project X11r6=3.3.3
Xfree86 Project X11r6=3.3.4
Xfree86 Project X11r6=3.3.5
Xfree86 Project X11r6=3.3.6
Xfree86 Project X11r6=4.0
Xfree86 Project X11r6=4.0.1
Xfree86 Project X11r6=4.0.2.11
Xfree86 Project X11r6=4.0.3
Xfree86 Project X11r6=4.1.0
Xfree86 Project X11r6=4.1.11
Xfree86 Project X11r6=4.1.12
Xfree86 Project X11r6=4.2.0
Xfree86 Project X11r6=4.2.1
Xfree86 Project X11r6=4.2.1
Xfree86 Project X11r6=4.3.0
Xfree86 Project X11r6=4.3.0.1
Xfree86 Project X11r6=4.3.0.2
Altlinux Alt Linux=2.3
Altlinux Alt Linux=2.3
Mandrakesoft Mandrake Linux=10.0
Mandrakesoft Mandrake Linux=10.0
Mandrakesoft Mandrake Linux=10.1
Mandrakesoft Mandrake Linux=10.1
Mandrakesoft Mandrake Linux=10.2
Mandrakesoft Mandrake Linux=10.2
Mandrakesoft Mandrake Linux Corporate Server=2.1
Mandrakesoft Mandrake Linux Corporate Server=2.1
Mandrakesoft Mandrake Linux Corporate Server=3.0
Mandrakesoft Mandrake Linux Corporate Server=3.0
redhat Enterprise Linux=3.0
redhat Enterprise Linux=3.0
redhat Enterprise Linux=3.0
redhat Enterprise Linux=4.0
redhat Enterprise Linux=4.0
redhat Enterprise Linux=4.0
redhat Enterprise Linux Desktop=3.0
redhat Enterprise Linux Desktop=4.0
redhat Fedora Core=core_2.0
redhat Fedora Core=core_3.0
SUSE SuSE Linux=6.1
SUSE SuSE Linux=6.1-alpha
SUSE SuSE Linux=6.2
SUSE SuSE Linux=6.3
SUSE SuSE Linux=6.3
SUSE SuSE Linux=6.3-alpha
SUSE SuSE Linux=6.4
SUSE SuSE Linux=6.4
SUSE SuSE Linux=6.4
SUSE SuSE Linux=6.4-alpha
SUSE SuSE Linux=7.0
SUSE SuSE Linux=7.0
SUSE SuSE Linux=7.0
SUSE SuSE Linux=7.0
SUSE SuSE Linux=7.0-alpha
SUSE SuSE Linux=7.1
SUSE SuSE Linux=7.1
SUSE SuSE Linux=7.1
SUSE SuSE Linux=7.1
SUSE SuSE Linux=7.1-alpha
SUSE SuSE Linux=7.2
SUSE SuSE Linux=7.2
SUSE SuSE Linux=7.3
SUSE SuSE Linux=7.3
SUSE SuSE Linux=7.3
SUSE SuSE Linux=7.3
SUSE SuSE Linux=8.0
SUSE SuSE Linux=8.0
SUSE SuSE Linux=8.1
SUSE SuSE Linux=8.2
SUSE SuSE Linux=9.0
SUSE SuSE Linux=9.0
SUSE SuSE Linux=9.1
SUSE SuSE Linux=9.1
SUSE SuSE Linux=9.2
SUSE SuSE Linux=9.2
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Mar 2, 2005
CVE Published
05:00 AM
Mar 4, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0605?
CVE-2005-0605 is classified as a high severity vulnerability due to the potential for arbitrary code execution via a buffer overflow.
2
How do I fix CVE-2005-0605?
To mitigate CVE-2005-0605, update to the latest version of the affected software that includes the security patch.
3
Which versions are affected by CVE-2005-0605?
CVE-2005-0605 affects specific versions of XFree86 and X.org, including versions 3.3.4, 4.1.0, and others listed in the vulnerability report.
4
What type of vulnerability is CVE-2005-0605?
CVE-2005-0605 is a buffer overflow vulnerability that arises from a negative bitmap_unit value in LibXPM.
5
Can CVE-2005-0605 be exploited remotely?
Yes, CVE-2005-0605 can be exploited remotely if the vulnerable application is exposed to untrusted input.