{
  "threat_severity" : "Moderate",
  "public_date" : "2004-09-15T00:00:00Z",
  "bugzilla" : {
    "description" : "openmotif21 stack overflows in libxpm",
    "id" : "430515",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=430515"
  },
  "details" : [ "Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malformed XPM image file." ],
  "statement" : "Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 3",
    "release_date" : "2004-10-04T00:00:00Z",
    "advisory" : "RHSA-2004:478",
    "cpe" : "cpe:/o:redhat:enterprise_linux:3",
    "package" : "XFree86-0:4.3.0-69.EL"
  }, {
    "product_name" : "Red Hat Enterprise Linux 3",
    "release_date" : "2004-12-02T00:00:00Z",
    "advisory" : "RHSA-2004:537",
    "cpe" : "cpe:/o:redhat:enterprise_linux:3",
    "package" : "openmotif-0:2.2.3-4.RHEL3.4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 3",
    "release_date" : "2004-12-02T00:00:00Z",
    "advisory" : "RHSA-2004:537",
    "cpe" : "cpe:/o:redhat:enterprise_linux:3",
    "package" : "openmotif21-0:2.1.30-9.RHEL3.4"
  }, {
    "product_name" : "Red Hat Enterprise Linux AS (Advanced Server) version 2.1",
    "release_date" : "2004-10-06T00:00:00Z",
    "advisory" : "RHSA-2004:479",
    "cpe" : "cpe:/o:redhat:enterprise_linux:2.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux AS (Advanced Server) version 2.1",
    "release_date" : "2005-01-12T00:00:00Z",
    "advisory" : "RHSA-2005:004",
    "cpe" : "cpe:/o:redhat:enterprise_linux:2.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux ES version 2.1",
    "release_date" : "2004-10-06T00:00:00Z",
    "advisory" : "RHSA-2004:479",
    "cpe" : "cpe:/o:redhat:enterprise_linux:2.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux ES version 2.1",
    "release_date" : "2005-01-12T00:00:00Z",
    "advisory" : "RHSA-2005:004",
    "cpe" : "cpe:/o:redhat:enterprise_linux:2.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux WS version 2.1",
    "release_date" : "2004-10-06T00:00:00Z",
    "advisory" : "RHSA-2004:479",
    "cpe" : "cpe:/o:redhat:enterprise_linux:2.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux WS version 2.1",
    "release_date" : "2005-01-12T00:00:00Z",
    "advisory" : "RHSA-2005:004",
    "cpe" : "cpe:/o:redhat:enterprise_linux:2.1"
  }, {
    "product_name" : "Red Hat Linux Advanced Workstation 2.1",
    "release_date" : "2004-10-06T00:00:00Z",
    "advisory" : "RHSA-2004:479",
    "cpe" : "cpe:/o:redhat:enterprise_linux:2.1"
  }, {
    "product_name" : "Red Hat Linux Advanced Workstation 2.1",
    "release_date" : "2005-01-12T00:00:00Z",
    "advisory" : "RHSA-2005:004",
    "cpe" : "cpe:/o:redhat:enterprise_linux:2.1"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 4.2",
    "release_date" : "2008-06-30T00:00:00Z",
    "advisory" : "RHSA-2008:0524",
    "cpe" : "cpe:/a:redhat:network_satellite:4.2::el4",
    "package" : "jabberd-0:2.0s10-3.38.rhn"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 4.2",
    "release_date" : "2008-06-30T00:00:00Z",
    "advisory" : "RHSA-2008:0524",
    "cpe" : "cpe:/a:redhat:network_satellite:4.2::el4",
    "package" : "java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 4.2",
    "release_date" : "2008-06-30T00:00:00Z",
    "advisory" : "RHSA-2008:0524",
    "cpe" : "cpe:/a:redhat:network_satellite:4.2::el4",
    "package" : "jfreechart-0:0.9.20-3.rhn"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 4.2",
    "release_date" : "2008-06-30T00:00:00Z",
    "advisory" : "RHSA-2008:0524",
    "cpe" : "cpe:/a:redhat:network_satellite:4.2::el4",
    "package" : "openmotif21-0:2.1.30-11.RHEL4.6"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 4.2",
    "release_date" : "2008-06-30T00:00:00Z",
    "advisory" : "RHSA-2008:0524",
    "cpe" : "cpe:/a:redhat:network_satellite:4.2::el4",
    "package" : "perl-Crypt-CBC-0:2.24-1.el4"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 4.2",
    "release_date" : "2008-06-30T00:00:00Z",
    "advisory" : "RHSA-2008:0524",
    "cpe" : "cpe:/a:redhat:network_satellite:4.2::el4",
    "package" : "rhn-apache-0:1.3.27-36.rhn.rhel4"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 4.2",
    "release_date" : "2008-06-30T00:00:00Z",
    "advisory" : "RHSA-2008:0524",
    "cpe" : "cpe:/a:redhat:network_satellite:4.2::el4",
    "package" : "rhn-modjk-0:1.2.23-2rhn.rhel4"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 4.2",
    "release_date" : "2008-06-30T00:00:00Z",
    "advisory" : "RHSA-2008:0524",
    "cpe" : "cpe:/a:redhat:network_satellite:4.2::el4",
    "package" : "rhn-modperl-0:1.29-16.rhel4"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 4.2",
    "release_date" : "2008-06-30T00:00:00Z",
    "advisory" : "RHSA-2008:0524",
    "cpe" : "cpe:/a:redhat:network_satellite:4.2::el4",
    "package" : "rhn-modssl-0:2.8.12-8.rhn.10.rhel4"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 4.2",
    "release_date" : "2008-06-30T00:00:00Z",
    "advisory" : "RHSA-2008:0524",
    "cpe" : "cpe:/a:redhat:network_satellite:4.2::el4",
    "package" : "tomcat5-0:5.0.30-0jpp_10rh"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 4.2 (RHEL3)",
    "release_date" : "2008-06-30T00:00:00Z",
    "advisory" : "RHSA-2008:0524",
    "cpe" : "cpe:/a:redhat:network_satellite:4.2::el3",
    "package" : "jabberd-0:2.0s10-3.37.rhn"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 4.2 (RHEL3)",
    "release_date" : "2008-06-30T00:00:00Z",
    "advisory" : "RHSA-2008:0524",
    "cpe" : "cpe:/a:redhat:network_satellite:4.2::el3",
    "package" : "java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el3"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 4.2 (RHEL3)",
    "release_date" : "2008-06-30T00:00:00Z",
    "advisory" : "RHSA-2008:0524",
    "cpe" : "cpe:/a:redhat:network_satellite:4.2::el3",
    "package" : "jfreechart-0:0.9.20-3.rhn"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 4.2 (RHEL3)",
    "release_date" : "2008-06-30T00:00:00Z",
    "advisory" : "RHSA-2008:0524",
    "cpe" : "cpe:/a:redhat:network_satellite:4.2::el3",
    "package" : "openmotif21-0:2.1.30-9.RHEL3.8"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 4.2 (RHEL3)",
    "release_date" : "2008-06-30T00:00:00Z",
    "advisory" : "RHSA-2008:0524",
    "cpe" : "cpe:/a:redhat:network_satellite:4.2::el3",
    "package" : "perl-Crypt-CBC-0:2.24-1.el3"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 4.2 (RHEL3)",
    "release_date" : "2008-06-30T00:00:00Z",
    "advisory" : "RHSA-2008:0524",
    "cpe" : "cpe:/a:redhat:network_satellite:4.2::el3",
    "package" : "rhn-apache-0:1.3.27-36.rhn.rhel3"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 4.2 (RHEL3)",
    "release_date" : "2008-06-30T00:00:00Z",
    "advisory" : "RHSA-2008:0524",
    "cpe" : "cpe:/a:redhat:network_satellite:4.2::el3",
    "package" : "rhn-modjk-0:1.2.23-2rhn.rhel3"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 4.2 (RHEL3)",
    "release_date" : "2008-06-30T00:00:00Z",
    "advisory" : "RHSA-2008:0524",
    "cpe" : "cpe:/a:redhat:network_satellite:4.2::el3",
    "package" : "rhn-modperl-0:1.29-16.rhel3"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 4.2 (RHEL3)",
    "release_date" : "2008-06-30T00:00:00Z",
    "advisory" : "RHSA-2008:0524",
    "cpe" : "cpe:/a:redhat:network_satellite:4.2::el3",
    "package" : "rhn-modssl-0:2.8.12-8.rhn.10.rhel3"
  }, {
    "product_name" : "Red Hat Network Satellite Server v 4.2 (RHEL3)",
    "release_date" : "2008-06-30T00:00:00Z",
    "advisory" : "RHSA-2008:0524",
    "cpe" : "cpe:/a:redhat:network_satellite:4.2::el3",
    "package" : "tomcat5-0:5.0.30-0jpp_10rh"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2004-0688\nhttps://nvd.nist.gov/vuln/detail/CVE-2004-0688" ],
  "name" : "CVE-2004-0688",
  "csaw" : false
}