PT-2011-1401 · Abcm2Ps+1 · Abcm2Ps+1
Publicado
2011-02-18
·
Atualizado
2020-08-14
·
CVE-2010-3441
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
abcm2ps versions prior to 5.9.12
Description
The issue is related to multiple buffer overflows that could allow remote attackers to execute arbitrary code. This can be achieved through a crafted input file related to the PUT0 and PUT1 output macros, or a crafted input file related to the
trim title function. Additionally, a long -O option on a command line might also be a potential attack vector.Recommendations
For versions prior to 5.9.12, update to version 5.9.12 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
PUT0 and PUT1 output macros, and the trim title function, until a patch is available. Avoid using long -O options on the command line until the issue is resolved.Correção
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Abcm2Ps