Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.1.1.2010.2026
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2026-1)
Summary:The remote host is missing an update for the Debian 'netpbm-free' package(s) announced via the DSA-2026-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'netpbm-free' package(s) announced via the DSA-2026-1 advisory.

Vulnerability Insight:
Marc Schoenefeld discovered a stack-based buffer overflow in the XPM reader implementation in netpbm-free, a suite of image manipulation utilities. An attacker could cause a denial of service (application crash) or possibly execute arbitrary code via an XPM image file that contains a crafted header field associated with a large color index value.

For the stable distribution (lenny), this problem has been fixed in version 2:10.0-12+lenny1.

For the testing distribution (squeeze), this problem has been fixed in version 2:10.0-12.1+squeeze1.

For the unstable distribution (sid), this problem will be fixed soon.

Due to a problem with the archive system it is not possible to release all architectures. The missing architectures will be installed into the archive once they become available.

We recommend that you upgrade your netpbm-free package.

Affected Software/OS:
'netpbm-free' package(s) on Debian 5.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-4274
38164
http://www.securityfocus.com/bid/38164
38530
http://secunia.com/advisories/38530
38915
http://secunia.com/advisories/38915
ADV-2010-0358
http://www.vupen.com/english/advisories/2010/0358
ADV-2010-0780
http://www.vupen.com/english/advisories/2010/0780
DSA-2026
http://www.debian.org/security/2010/dsa-2026
MDVSA-2010:039
http://www.mandriva.com/security/advisories?name=MDVSA-2010:039
RHSA-2011:1811
http://www.redhat.com/support/errata/RHSA-2011-1811.html
SUSE-SR:2010:006
http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html
[oss-security] 20100209 vulnerability in netpbm (CVE-2009-4274)
http://www.openwall.com/lists/oss-security/2010/02/09/11
http://netpbm.svn.sourceforge.net/viewvc/netpbm/stable/converter/ppm/xpmtoppm.c?view=patch&r1=995&r2=1076&pathrev=1076
http://netpbm.svn.sourceforge.net/viewvc/netpbm/stable/doc/HISTORY?view=markup
https://bugzilla.redhat.com/show_bug.cgi?id=546580
netpbm-xpm-bo(56207)
https://exchange.xforce.ibmcloud.com/vulnerabilities/56207
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.