Lucene search

K
cve[email protected]CVE-2005-3178
HistoryOct 07, 2005 - 6:02 p.m.

CVE-2005-3178

2005-10-0718:02:00
web.nvd.nist.gov
29
buffer overflow
xloadimage
xli
niff file
security vulnerability
code execution
cve-2005-3178

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

7.3 High

AI Score

Confidence

Low

0.029 Low

EPSS

Percentile

90.9%

Buffer overflow in xloadimage 4.1 and earlier, and xli, might allow user-assisted attackers to execute arbitrary code via a long title name in a NIFF file, which triggers the overflow during (1) zoom, (2) reduce, or (3) rotate operations.

Affected configurations

NVD
Node
xlixli
OR
xloadimagexloadimageRange4.1

References

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

7.3 High

AI Score

Confidence

Low

0.029 Low

EPSS

Percentile

90.9%