PT-2006-1014 · Abcm2Ps · Abcm2Ps

Erik Sjölund

·

Published

2006-04-25

·

Updated

2017-07-20

·

CVE-2006-1513

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: abc2ps versions prior to 1.3.3
Description: The issue concerns multiple buffer overflows in the abc2ps package, which can be exploited to execute arbitrary code via crafted ABC music files. This can lead to a breach of confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely.
Recommendations: For versions prior to 1.3.3, update to version 1.3.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of crafted ABC music files until a patch is available. Avoid using the abc2ps package with untrusted input files until the issue is resolved.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03036
CVE-2006-1513
DSA-1041-1

Affected Products

Abcm2Ps