VYPR
Unrated severityNVD Advisory· Published Oct 20, 2004· Updated Apr 16, 2026

CVE-2004-0688

CVE-2004-0688

Description

Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malformed XPM image file.

Affected products

23
  • Xorg/X11r614 versions
    cpe:2.3:a:x.org:x11r6:6.7.0:*:*:*:*:*:*:*+ 13 more
    • cpe:2.3:a:x.org:x11r6:6.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:x.org:x11r6:6.8:*:*:*:*:*:*:*
    • cpe:2.3:a:xfree86_project:x11r6:3.3.6:*:*:*:*:*:*:*
    • cpe:2.3:a:xfree86_project:x11r6:4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:xfree86_project:x11r6:4.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:xfree86_project:x11r6:4.0.2.11:*:*:*:*:*:*:*
    • cpe:2.3:a:xfree86_project:x11r6:4.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:xfree86_project:x11r6:4.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:xfree86_project:x11r6:4.1.11:*:*:*:*:*:*:*
    • cpe:2.3:a:xfree86_project:x11r6:4.1.12:*:*:*:*:*:*:*
    • cpe:2.3:a:xfree86_project:x11r6:4.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:xfree86_project:x11r6:4.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:xfree86_project:x11r6:4.2.1:*:errata:*:*:*:*:*
    • cpe:2.3:a:xfree86_project:x11r6:4.3.0:*:*:*:*:*:*:*
  • OpenBSD/OpenBSD2 versions
    cpe:2.3:o:openbsd:openbsd:3.4:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:openbsd:openbsd:3.4:*:*:*:*:*:*:*
    • cpe:2.3:o:openbsd:openbsd:3.5:*:*:*:*:*:*:*
  • SUSE S.A./Linux7 versions
    cpe:2.3:o:suse:suse_linux:8:*:enterprise_server:*:*:*:*:*+ 6 more
    • cpe:2.3:o:suse:suse_linux:8:*:enterprise_server:*:*:*:*:*
    • cpe:2.3:o:suse:suse_linux:8.1:*:*:*:*:*:*:*
    • cpe:2.3:o:suse:suse_linux:8.2:*:*:*:*:*:*:*
    • cpe:2.3:o:suse:suse_linux:9.0:*:*:*:*:*:*:*
    • cpe:2.3:o:suse:suse_linux:9.0:*:enterprise_server:*:*:*:*:*
    • cpe:2.3:o:suse:suse_linux:9.0:*:x86_64:*:*:*:*:*
    • cpe:2.3:o:suse:suse_linux:9.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

23

News mentions

0

No linked articles in our index yet.