xv: Filename handling vulnerability xv contains a format string vulnerability, potentially resulting in the execution of arbitrary code. xv March 04, 2005 May 22, 2006: 02 83686 remote 3.10a-r10 3.10a-r10

xv is an interactive image manipulation package for X11.

Tavis Ormandy of the Gentoo Linux Security Audit Team identified a flaw in the handling of image filenames by xv.

Successful exploitation would require a victim to process a specially crafted image with a malformed filename, potentially resulting in the execution of arbitrary code.

There is no known workaround at this time.

All xv users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=media-gfx/xv-3.10a-r10"
CVE-2005-0665 koon taviso koon