PT-2006-1014 · Abcm2Ps · Abcm2Ps
Erik Sjölund
·
Published
2006-04-25
·
Updated
2017-07-20
·
CVE-2006-1513
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
abc2ps versions prior to 1.3.3
Description:
The issue concerns multiple buffer overflows in the abc2ps package, which can be exploited to execute arbitrary code via crafted ABC music files. This can lead to a breach of confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely.
Recommendations:
For versions prior to 1.3.3, update to version 1.3.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of crafted ABC music files until a patch is available. Avoid using the abc2ps package with untrusted input files until the issue is resolved.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abcm2Ps