Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.64817
Category:Fedora Local Security Checks
Title:Fedora Core 11 FEDORA-2009-8993 (xemacs)
Summary:The remote host is missing an update to xemacs;announced via advisory FEDORA-2009-8993.;Note: This VT has been deprecated and is therefore no longer functional.
Description:Summary:
The remote host is missing an update to xemacs
announced via advisory FEDORA-2009-8993.
Note: This VT has been deprecated and is therefore no longer functional.

Vulnerability Insight:
Update Information:

This update fixes multiple buffer overflows when reading large image files, or
maliciously created image files whose headers misrepresent the actual image
size.

The update also addresses multiple font issues, some of which cause
warnings on startup. Some warnings remain, however, unless an ISO8859-13 fonts
(e.g., terminus) is installed. Also note that some warnings remain on Rawhide
pending a resolution for bz 507637.

ChangeLog:

* Mon Aug 24 2009 Jerry James - 21.5.29-2

- Fix image overflow bug (CVE-2009-2688).

- Fix calling xft-font-create-object in non-Xft builds (#512623).

- Rebase patches to eliminate fuzz/offsets.

Solution:
Apply the appropriate updates.

This update can be installed with the yum update program. Use
su -c 'yum update xemacs' at the command line.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-2688
BugTraq ID: 35473
http://www.securityfocus.com/bid/35473
http://tracker.xemacs.org/XEmacs/its/issue534
http://osvdb.org/55298
http://secunia.com/advisories/35348
http://www.vupen.com/english/advisories/2009/1666
XForce ISS Database: xemacs-jpeg-bo(51334)
https://exchange.xforce.ibmcloud.com/vulnerabilities/51334
XForce ISS Database: xemacs-png-bo(51333)
https://exchange.xforce.ibmcloud.com/vulnerabilities/51333
XForce ISS Database: xemacs-tiff-bo(51332)
https://exchange.xforce.ibmcloud.com/vulnerabilities/51332
CopyrightCopyright (C) 2009 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.