PT-2006-7565 · Abcmidi · Abcmidi

Erik Sjölund

·

Publicado

1970-01-01

·

Atualizado

2011-03-08

·

CVE-2006-1514

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions abcmidi versions 20050101 and earlier
Description The issue concerns multiple buffer overflows in the abcmidi-yaps translator, which can be exploited remotely. This can lead to the execution of arbitrary code via crafted ABC music files that trigger the overflows during translation into PostScript, potentially disrupting the confidentiality, integrity, and availability of protected information.
Recommendations For abcmidi version 20050101 and earlier, update to a version that contains a fix for this issue to prevent remote attackers from executing arbitrary code. As a temporary workaround, consider restricting the use of the abcmidi-yaps translator until a patch is available. Avoid using the abcmidi package with untrusted ABC music files until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-03559
BDU:2015-03560
CVE-2006-1514
DSA-1043-1

Produtos afetados

Abcmidi