CVE-2004-0688

Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malformed XPM image file.

Date published : 2004-09-24

http://lists.apple.com/archives/security-announce/2005/May/msg00001.html

http://www.securityfocus.com/bid/11196