2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2005-0638" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2005-03-02T05:00:00.000" ,
2025-04-03 02:06:18 +00:00
"lastModified" : "2025-04-03T01:03:51.193" ,
"vulnStatus" : "Deferred" ,
2024-12-08 03:06:42 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:L/Au:N/C:P/I:P/A:P" ,
2024-11-21 23:11:37 +00:00
"baseScore" : 7.5 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "PARTIAL" ,
2024-11-21 23:11:37 +00:00
"availabilityImpact" : "PARTIAL"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "HIGH" ,
"exploitabilityScore" : 10.0 ,
"impactScore" : 6.4 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : true ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-Other"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:xli:xli:1.14:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D053A59C-7C9C-42B9-82CD-B6E8D6D405C8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:xli:xli:1.15:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "29A8E75C-D3DD-472D-8E9E-BBB4F753F506"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:xli:xli:1.16:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "44737F18-0C52-451E-9555-0A222F02B321"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:xli:xli:1.17:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6EE9AD48-3D2F-44AD-9950-494B14E3FC33"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:altlinux:alt_linux:2.3:*:compact:*:*:*:*:*" ,
"matchCriteriaId" : "64BE98C2-8EFA-4349-9FE2-D62CA63A16C4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:altlinux:alt_linux:2.3:*:junior:*:*:*:*:*" ,
"matchCriteriaId" : "7D0AC3A3-A37C-4053-B05F-A031877AC811"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "02EE2D72-B1E6-4380-80B0-E40A23DDD115"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:2.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "111575DE-98A2-4C54-BDE1-CACC74D22B35"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1976D15D-9EE6-4A49-B59F-34F0505FD5BC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:4.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "962FC8D7-BE5D-4E7D-9ADC-511681C593BF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:4.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "451453AC-65FF-4E3B-9AC1-2DDB2E2182E4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:4.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7716120D-5110-42B0-A574-9AA2AC8D3C32"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:4.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CB4C8426-CAF2-4366-94C0-1BA1C544FB6F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:4.4.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5CC7D746-B98B-4FAF-B816-57222759A344"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:5.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "830D48B8-D21D-4D31-99A1-20C231804DBE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:5.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5C0BBDD2-9FF9-4CB7-BCAF-D4AF15DC2C7C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:5.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D1C826AA-6E2F-4DAC-A7A2-9F47729B5DA5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:5.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BCC94EF9-5872-402F-B2FC-06331A924BB2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:6.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F163E145-09F7-4BE2-9B46-5B6713070BAB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:6.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "124E1802-7984-45ED-8A92-393FC20662FD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:6.1:alpha:*:*:*:*:*:*" ,
"matchCriteriaId" : "C7F08806-9458-439A-8EAE-2553122262ED"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:6.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1B67020A-6942-4478-B501-764147C4970D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:6.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0AD0FF64-05DF-48C2-9BB5-FD993121FB2E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:6.3:*:ppc:*:*:*:*:*" ,
"matchCriteriaId" : "E74E0A28-7C78-4160-8BCF-99605285C0EE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:6.3:alpha:*:*:*:*:*:*" ,
"matchCriteriaId" : "76159C25-0760-47CB-AFCE-28306CDEA830"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:6.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7786607A-362E-4817-A17E-C76D6A1F737D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:6.4:*:i386:*:*:*:*:*" ,
"matchCriteriaId" : "8A206E1C-C2EC-4356-8777-B18D7069A4C3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:6.4:*:ppc:*:*:*:*:*" ,
"matchCriteriaId" : "6E2FE291-1142-4627-A497-C0BB0D934A0B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:6.4:alpha:*:*:*:*:*:*" ,
"matchCriteriaId" : "49BC7C7E-046C-4186-822E-9F3A2AD3577B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:7.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C9E7D75A-333E-4C63-9593-F64ABA5D1CE3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:7.0:*:i386:*:*:*:*:*" ,
"matchCriteriaId" : "2FE69F6F-6B17-4C87-ACA4-A2A1FB47206A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:7.0:*:ppc:*:*:*:*:*" ,
"matchCriteriaId" : "467A30EB-CB8F-4928-AC8F-F659084A9E2B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:7.0:*:sparc:*:*:*:*:*" ,
"matchCriteriaId" : "714C1439-AB8E-4A8B-A783-D60E9DDC38D4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:7.0:alpha:*:*:*:*:*:*" ,
"matchCriteriaId" : "62CAE5B0-4D46-4A93-A343-C8E9CB574C62"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:7.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "819868A7-EB1E-4CA9-8D71-72F194E5EFEB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:7.1:*:spa:*:*:*:*:*" ,
"matchCriteriaId" : "FB647A8B-ADB9-402B-96E1-45321C75731B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:7.1:*:sparc:*:*:*:*:*" ,
"matchCriteriaId" : "0944FD27-736E-4B55-8D96-9F2CA9BB9B05"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:7.1:*:x86:*:*:*:*:*" ,
"matchCriteriaId" : "373BB5AC-1F38-4D0A-97DC-08E9654403EE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:7.1:alpha:*:*:*:*:*:*" ,
"matchCriteriaId" : "B5E71DA3-F4A0-46AF-92A2-E691C7A65528"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:7.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0519FF7D-363E-4530-9E63-6EA3E88432DC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:7.2:*:i386:*:*:*:*:*" ,
"matchCriteriaId" : "1975A2DD-EB22-4ED3-8719-F78AA7F414B2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:7.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FAE3FF4F-646F-4E05-A08A-C9399DEF60F1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:7.3:*:i386:*:*:*:*:*" ,
"matchCriteriaId" : "19F606EE-530F-4C06-82DB-52035EE03FA3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:7.3:*:ppc:*:*:*:*:*" ,
"matchCriteriaId" : "A0E896D5-0005-4E7E-895D-B202AFCE09A1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:7.3:*:sparc:*:*:*:*:*" ,
"matchCriteriaId" : "5A8B313F-93C7-4558-9571-DE1111487E17"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:8.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "28CD54FE-D682-4063-B7C3-8B29B26B39AD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:8.0:*:i386:*:*:*:*:*" ,
"matchCriteriaId" : "37F124FE-15F1-49D7-9E03-8E036CE1A20C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:8.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F8C55338-3372-413F-82E3-E1B476D6F41A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:8.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1EFB33BF-F6A5-48C1-AEB5-194FCBCFC958"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:9.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FB0E2D3B-B50A-46C2-BA1E-3E014DE91954"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:9.0:*:x86_64:*:*:*:*:*" ,
"matchCriteriaId" : "56EF103F-5668-4754-A83B-D3662D0CE815"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:9.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CFABFCE5-4F86-4AE8-9849-BC360AC72098"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:9.1:*:x86_64:*:*:*:*:*" ,
"matchCriteriaId" : "D5F98B9A-880E-45F0-8C16-12B22970F0D1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:9.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CFF36BC6-6CCD-4FEE-A120-5B8C4BF5620C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:9.2:*:x86_64:*:*:*:*:*" ,
"matchCriteriaId" : "B905C6E9-5058-4FD7-95B6-CD6AB6B2F516"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:suse:suse_linux:9.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A7D073E9-E535-4B36-BEF2-8499536E37DA"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://bugs.gentoo.org/show_bug.cgi?id=79762" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
} ,
2024-04-04 08:46:00 +00:00
{
"url" : "http://secunia.com/advisories/14459" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "http://secunia.com/advisories/14462" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
} ,
2023-04-24 12:24:31 +02:00
{
"url" : "http://security.gentoo.org/glsa/glsa-200503-05.xml" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://support.avaya.com/elmodocs2/security/ASA-2005-134_RHSA-2005-332.pdf" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www.debian.org/security/2005/dsa-695" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
} ,
2024-04-04 08:46:00 +00:00
{
"url" : "http://www.osvdb.org/14365" ,
"source" : "cve@mitre.org"
} ,
2023-04-24 12:24:31 +02:00
{
"url" : "http://www.redhat.com/support/errata/RHSA-2005-332.html" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www.securityfocus.com/archive/1/433935/30/5010/threaded" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www.securityfocus.com/bid/12712" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10898" ,
"source" : "cve@mitre.org"
2024-11-21 23:11:37 +00:00
} ,
{
"url" : "http://bugs.gentoo.org/show_bug.cgi?id=79762" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://secunia.com/advisories/14459" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "http://secunia.com/advisories/14462" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://security.gentoo.org/glsa/glsa-200503-05.xml" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://support.avaya.com/elmodocs2/security/ASA-2005-134_RHSA-2005-332.pdf" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.debian.org/security/2005/dsa-695" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://www.osvdb.org/14365" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.redhat.com/support/errata/RHSA-2005-332.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.securityfocus.com/archive/1/433935/30/5010/threaded" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.securityfocus.com/bid/12712" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10898" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2023-04-24 12:24:31 +02:00
}
]
}