DSA-069Vendor advisory
http://www.debian.org/security/2001/dsa-069 CVE-2001-0775
xloadimage 4.1 - Remote Buffer Overflow
Record summary
CVE-2001-0775 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attackers to execute arbitrary code via a FACES format image containing a long (1) Firstname or (2) Lastname field.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBxloadimage 4.1 - Remote Buffer OverflowExploitDB exploitby zenith parsecNot analyzed1 file
References
9DSA-695Vendor advisory
http://www.debian.org/security/2005/dsa-695 GLSA-200503-05Vendor advisory
http://www.gentoo.org/security/en/glsa/glsa-200503-05.xml xloadimage-faces-bo(6821)vdb entry
http://www.iss.net/security_center/static/6821.php SA:2001:024Vendor advisory
http://www.novell.com/linux/security/advisories/2001_024_xli_txt.html RHSA-2001:088Vendor advisory
http://www.redhat.com/support/errata/RHSA-2001-088.html 20010710 xloadimage remote exploit - tstot.cmailing list
http://www.securityfocus.com/archive/1/195823 3006vdb entry
http://www.securityfocus.com/bid/3006 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0775