Vulnerabilities > CVE-2005-0665 - Unspecified vulnerability in John Bradley XV 3.10A

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
john-bradley
nessus

Summary

Format string vulnerability in xv before 3.10a allows remote attackers to execute arbitrary code via format string specifiers in a filename.

Vulnerable Configurations

Part Description Count
Application
John_Bradley
1

Nessus

  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-200503-09.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-200503-09 (xv: Filename handling vulnerability) Tavis Ormandy of the Gentoo Linux Security Audit Team identified a flaw in the handling of image filenames by xv. Impact : Successful exploitation would require a victim to process a specially crafted image with a malformed filename, potentially resulting in the execution of arbitrary code. Workaround : There is no known workaround at this time.
    last seen2020-06-01
    modified2020-06-02
    plugin id17275
    published2005-03-06
    reporterThis script is Copyright (C) 2005-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/17275
    titleGLSA-200503-09 : xv: Filename handling vulnerability
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_A4BD30399A4811D9A2560001020EED82.NASL
    descriptionA Gentoo Linux Security Advisory reports : Tavis Ormandy of the Gentoo Linux Security Audit Team identified a flaw in the handling of image filenames by xv. Successful exploitation would require a victim to process a specially crafted image with a malformed filename, potentially resulting in the execution of arbitrary code.
    last seen2020-06-01
    modified2020-06-02
    plugin id19060
    published2005-07-13
    reporterThis script is Copyright (C) 2005-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/19060
    titleFreeBSD : xv -- filename handling format string vulnerability (a4bd3039-9a48-11d9-a256-0001020eed82)