Title : SCO Security Update Fixes Xloadimage Buffer Overflow Vulnerabilities VUPEN ID : VUPEN/ADV-2005-3025 CVE ID : CVE-2005-3178
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-12-21
Technical Description
SCO has released updated packages for OpenServer to address multiple vulnerabilities identified in Xloadimage. These flaws are due to buffer overflow errors in "zoom.c", "reduce.c" and "rotate.c" when processing a specially crafted NIFF image containing an overly long title, which could be exploited by attackers to compromise a vulnerable system by convincing a user to open a malicious NIFF image. For additional information, see : VUPEN/ADV-2005-1990