CVE-2005-0638

Publication date 2 March 2005

Last updated 17 July 2025


Ubuntu priority

xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
xli 7.04 feisty
Fixed 1.17.0-21
6.10 edgy
Fixed 1.17.0-21
6.06 LTS dapper
Fixed 1.17.0-21
xloadimage 7.04 feisty
Fixed 4.1-16
6.10 edgy
Fixed 4.1-16
6.06 LTS dapper
Fixed 4.1-16