PT-2010-1144 · Gnome+1 · Gmime+1

Jan Lieskovsky

·

Publicado

2010-02-08

·

Atualizado

2014-01-21

·

CVE-2010-0409

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GMime versions prior to 2.4.15 Gentoo Linux (affected versions not specified)
Description The issue concerns a buffer overflow in the GMIME UUENCODE LEN macro, which can be exploited to cause a denial of service or possibly execute arbitrary code via input data for a uuencode operation. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely.
Recommendations For GMime versions prior to 2.4.15, update to version 2.4.15 or later to resolve the issue. As a temporary workaround, consider restricting input data for uuencode operations to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09688
CVE-2010-0409
DSA-2082-1

Produtos afetados

Gmime
Gentoo Linux