漏洞信息详情
IMLib/IMLib2多个BMP图像解码缓冲区溢出漏洞
- CNNVD编号:CNNVD-200412-363
- 危害等级: 高危
- CVE编号:
CVE-2004-0817
- 漏洞类型:
缓冲区溢出
- 发布时间:
2004-12-31
- 威胁类型:
远程
- 更新时间:
2010-01-28
- 厂 商:
mandrakesoft - 漏洞来源:
Discovery of these… -
漏洞简介
imlib图像处理器存在多个基于堆的缓冲区溢出漏洞。远程攻击者可以借助畸形BMP文件执行代码。
漏洞公告
The vendor has addressed this issue in Imlib2 1.1.2. Reportedly, this fix is available through CVS:
http://cvs.sourceforge.net/viewcvs.py/enlightenment/e17/
Please see the referenced advisories for more information.
Sun Solaris 10
RedHat Fedora Core2
-
Fedora ImageMagick-6.2.0.7-2.fc2.4.legacy.i386.rpmRedHat Fedora Core 2
http://download.fedoralegacy.org/fedora/2/updates/i386/ImageMagick-6.2
.0.7-2.fc2.4.legacy.i386.rpm -
Fedora ImageMagick-c++-6.2.0.7-2.fc2.4.legacy.i386.rpmRedHat Fedora Core 2
http://download.fedoralegacy.org/fedora/2/updates/i386/ImageMagick-c++
-6.2.0.7-2.fc2.4.legacy.i386.rpm -
Fedora ImageMagick-c++-devel-6.2.0.7-2.fc2.4.legacy.i386.rpmRedHat Fedora Core 2
http://download.fedoralegacy.org/fedora/2/updates/i386/ImageMagick-c++
-devel-6.2.0.7-2.fc2.4.legacy.i386.rpm -
Fedora ImageMagick-devel-6.2.0.7-2.fc2.4.legacy.i386.rpmRedHat Fedora Core 2
http://download.fedoralegacy.org/fedora/2/updates/i386/ImageMagick-dev
el-6.2.0.7-2.fc2.4.legacy.i386.rpm -
Fedora ImageMagick-perl-6.2.0.7-2.fc2.4.legacy.i386.rpmRedHat Fedora Core 2
http://download.fedoralegacy.org/fedora/2/updates/i386/ImageMagick-per
l-6.2.0.7-2.fc2.4.legacy.i386.rpm
RedHat Fedora Core1
-
Fedora ImageMagick-5.5.6-13.legacy.i386.rpmRedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/ImageMagick-5.5
.6-13.legacy.i386.rpm -
Fedora ImageMagick-c++-5.5.6-13.legacy.i386.rpmRedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/ImageMagick-c++
-5.5.6-13.legacy.i386.rpm -
Fedora ImageMagick-c++-devel-5.5.6-13.legacy.i386.rpmRedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/ImageMagick-c++
-devel-5.5.6-13.legacy.i386.rpm -
Fedora ImageMagick-devel-5.5.6-13.legacy.i386.rpmRedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/ImageMagick-dev
el-5.5.6-13.legacy.i386.rpm -
Fedora ImageMagick-perl-5.5.6-13.legacy.i386.rpmRedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/ImageMagick-per
l-5.5.6-13.legacy.i386.rpm
Sun Solaris 10_x86
Sun Solaris 9
-
Sun 114636-04 (sun)
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21
-114636-04-1 -
Sun 137038-01
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21
-137038-01-1
Sun Solaris 9_x86
-
Sun 114637-04 (sun)
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21
-114637-04-1 -
Sun 137039-01
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21
-137039-01-1
Enlightenment Imlib2 1.0.5
-
Conectiva imlib2-1.0.6-26409U90_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/imlib2-1.0.6-26409U90_1cl.i
386.rpm -
Conectiva imlib2-1.0.6-58651U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/imlib2-1.0.6-58651U10_1cl.
i386.rpm -
Conectiva imlib2-devel-1.0.6-26409U90_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/imlib2-devel-1.0.6-26409U90
_1cl.i386.rpm -
Conectiva imlib2-devel-1.0.6-58651U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/imlib2-devel-1.0.6-58651U1
0_1cl.i386.rpm -
Conectiva imlib2-devel-static-1.0.6-26409U90_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/imlib2-devel-static-1.0.6-2
6409U90_1cl.i386.rpm -
Conectiva imlib2-devel-static-1.0.6-58651U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/imlib2-devel-static-1.0.6-
58651U10_1cl.i386.rpm -
Conectiva imlib2-filters-1.0.6-26409U90_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/imlib2-filters-1.0.6-26409U
90_1cl.i386.rpm -
Conectiva imlib2-filters-1.0.6-58651U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/imlib2-filters-1.0.6-58651
U10_1cl.i386.rpm -
Conectiva imlib2-loader_argb-1.0.6-26409U90_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/imlib2-loader_argb-1.0.6-26
409U90_1cl.i386.rpm -
Conectiva imlib2-loader_argb-1.0.6-58651U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/imlib2-loader_argb-1.0.6-5
8651U10_1cl.i386.rpm -
Conectiva imlib2-loader_bmp-1.0.6-26409U90_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/imlib2-loader_bmp-1.0.6-264
09U90_1cl.i386.rpm
参考网址
来源: XF
名称: imlib-bmp-bo(17182)
链接:http://xforce.iss.net/xforce/xfdb/17182
来源: BID
名称: 11084
链接:http://www.securityfocus.com/bid/11084
来源: REDHAT
名称: RHSA-2004:465
链接:http://www.redhat.com/support/errata/RHSA-2004-465.html
来源: GENTOO
名称: GLSA-200409-12
链接:http://www.gentoo.org/security/en/glsa/glsa-200409-12.xml
来源: DEBIAN
名称: DSA-548
链接:http://www.debian.org/security/2004/dsa-548
来源: CONECTIVA
名称: CLA-2004:870
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000870
来源: SUNALERT
名称: 201611
链接:http://sunsolve.sun.com/search/document.do?assetkey=1-66-201611-1
来源: OVAL
名称: oval:org.mitre.oval:def:8843
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8843
来源: MANDRAKE
名称: MDKSA-2004:089
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2004:089