Vulnerability Name:

CVE-2008-5187 (CCN-46739)

Assigned:2008-11-14
Published:2008-11-14
Updated:2011-03-08
Summary:The load function in the XPM loader for imlib2 1.4.2, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XPM file that triggers a "pointer arithmetic error" and a heap-based buffer overflow, a different vulnerability than CVE-2008-2426.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.6 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-119
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: Debian Bug report logs - #505714
Crash on loading XPM file

Source: CONFIRM
Type: UNKNOWN
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=505714#15

Source: MITRE
Type: CNA
CVE-2008-5187

Source: SUSE
Type: UNKNOWN
SUSE-SR:2009:002

Source: OSVDB
Type: UNKNOWN
49970

Source: CCN
Type: SA32796
imlib2 XPM Processing Buffer Overflow Vulnerability

Source: SECUNIA
Type: Vendor Advisory
32796

Source: SECUNIA
Type: UNKNOWN
32843

Source: SECUNIA
Type: UNKNOWN
32949

Source: SECUNIA
Type: UNKNOWN
32963

Source: SECUNIA
Type: UNKNOWN
33323

Source: SECUNIA
Type: UNKNOWN
33568

Source: GENTOO
Type: UNKNOWN
GLSA-200812-23

Source: DEBIAN
Type: UNKNOWN
DSA-1672

Source: DEBIAN
Type: DSA-1672
imlib2 -- buffer overflow

Source: CCN
Type: Enlightenment Web site
Enlightenment

Source: CCN
Type: GLSA-200812-23
Imlib2: User-assisted execution of arbitrary code

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2009:019

Source: MLIST
Type: UNKNOWN
[oss-security] 20081120 CVE Request: imlib2

Source: CCN
Type: OSVDB ID: 49970
imlib2 XPM Loader load() Function Crafted XPM File Handling Overflow

Source: BID
Type: UNKNOWN
32371

Source: CCN
Type: BID-32371
'imlib2' Library 'load()' Function Buffer Overflow Vulnerability

Source: CCN
Type: USN-683-1
Imlib2 vulnerability

Source: UBUNTU
Type: UNKNOWN
USN-683-1

Source: VUPEN
Type: UNKNOWN
ADV-2008-3212

Source: XF
Type: UNKNOWN
imlib2-load-bo(46739)

Source: FEDORA
Type: UNKNOWN
FEDORA-2008-10287

Source: FEDORA
Type: UNKNOWN
FEDORA-2008-10296

Source: SUSE
Type: SUSE-SR:2009:002
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:enlightenment:imlib2:1.4.2:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:enlightenment:imlib2:1.4.2:*:*:*:*:*:*:*
  • AND
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:6.06::lts:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0::x86_64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.0::x86-64:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:7.10:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.1:x86_64:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.1:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:8.04::lts:*:*:*:*:*
  • OR cpe:/o:mandriva:linux:2009.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandriva:linux:2009.0:-:x86_64:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20085187
    V
    CVE-2008-5187
    2022-06-30
    oval:org.opensuse.security:def:112434
    P
    imlib2-1.7.1-1.6 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:26175
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:105940
    P
    imlib2-1.7.1-1.6 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:36422
    P
    imlib2-1.4.2-2.18.53 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:26047
    P
    Security update for xen (Important)
    2021-05-12
    oval:org.opensuse.security:def:25983
    P
    Security update for openexr (Moderate)
    2020-12-23
    oval:org.opensuse.security:def:25971
    P
    Security update for fontforge (Moderate)
    2020-12-04
    oval:org.opensuse.security:def:25972
    P
    Security update for postgresql12 (Important)
    2020-12-04
    oval:org.opensuse.security:def:26601
    P
    libsamplerate on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26747
    P
    libgdiplus0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26313
    P
    Security update for python-requests (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26650
    P
    xdg-utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27385
    P
    cvs-doc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26397
    P
    Security update for plasma5-workspace (Important)
    2020-12-01
    oval:org.opensuse.security:def:26689
    P
    ed on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27420
    P
    imlib2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26548
    P
    freetype2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26703
    P
    fvwm2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26256
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.mitre.oval:def:17468
    P
    USN-683-1 -- imlib2 vulnerability
    2014-06-30
    oval:org.mitre.oval:def:8309
    P
    DSA-1672 imlib2 -- buffer overflow
    2014-06-23
    oval:org.mitre.oval:def:18566
    P
    DSA-1672-1 imlib2 - arbitrary code execution
    2014-06-23
    oval:org.debian:def:1672
    V
    buffer overflow
    2008-11-29
    BACK
    enlightenment imlib2 1.4.2
    enlightenment imlib2 1.4.2
    gentoo linux *
    mandrakesoft mandrake linux corporate server 3.0
    canonical ubuntu 6.06
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 3.0
    mandrakesoft mandrake linux 2008.0
    debian debian linux 4.0
    canonical ubuntu 7.10
    mandrakesoft mandrake linux 2008.0
    mandrakesoft mandrake linux 2008.1 x86_64
    mandrakesoft mandrake linux 2008.1
    canonical ubuntu 8.04
    mandriva linux 2009.0
    mandriva linux 2009.0 -