PT-2010-1148 · Gnustep · Gnustep-Base

Dan Rosenberg

+1

·

Publicado

2010-05-12

·

Atualizado

2014-01-20

·

CVE-2010-1620

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GNUstep Base versions prior to 1.20.0 GNUstep Base versions prior to 1.20.1
Description The issue is related to an integer overflow in the load iface function in Tools/gdomap.c in gdomap, which might allow attackers to execute arbitrary code via a file or socket that provides configuration data with many entries, leading to a heap-based buffer overflow. Additionally, there are multiple vulnerabilities in the gnustep-base package that can lead to violations of confidentiality, integrity, and availability of protected information, and these can be exploited locally.
Recommendations For versions prior to 1.20.0, update to version 1.20.0 or later. For versions prior to 1.20.1, update to version 1.20.1 or later. As a temporary workaround, consider restricting access to the load iface function in Tools/gdomap.c until a patch is available.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09691
CVE-2010-1620

Produtos afetados

Gnustep-Base