Title : SCO Security Update Fixes Xloadimage Buffer Overflow Vulnerabilities VUPEN ID : VUPEN/ADV-2005-2890 CVE ID : CVE-2005-3178
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-12-15
Technical Description
SCO has released updated packages for UnixWare to address multiple vulnerabilities identified in Xloadimage. These flaws are due to buffer overflow errors in "zoom.c", "reduce.c" and "rotate.c" when processing a specially crafted NIFF image containing an overly long title, which could be exploited by attackers to compromise a vulnerable system by convincing a user to open a malicious NIFF image. For additional information, see : VUPEN/ADV-2005-1990
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback If you have additional information or corrections for this security advisory please submit them via our contact form.