Oval Definition:oval:com.redhat.rhsa:def:20050802
Revision Date:2005-10-18Version:502
Title:RHSA-2005:802: xloadimage security update (Low)
Description:The xloadimage utility displays images in an X Window System window, loads images into the root window, or writes images into a file. Xloadimage supports many image types (including GIF, TIFF, JPEG, XPM, and XBM).

A flaw was discovered in xloadimage via which an attacker can construct a NIFF image with a very long embedded image title. This image can cause a buffer overflow. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-3178 to this issue.

All users of xloadimage should upgrade to this erratum package, which contains backported patches to correct these issues.
Family:unixClass:patch
Status:Reference(s):CVE-2005-3178
RHSA-2005:802-01
Platform(s):Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND xloadimage is earlier than 0:4.1-36.RHEL3
  • AND xloadimage is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND xloadimage is earlier than 0:4.1-36.RHEL4
  • AND xloadimage is signed with Red Hat master key
  • BACK