PT-2006-7565 · Abcmidi · Abcmidi

Erik Sjölund

·

Published

1970-01-01

·

Updated

2011-03-08

·

CVE-2006-1514

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions abcmidi versions 20050101 and earlier
Description The issue concerns multiple buffer overflows in the abcmidi-yaps translator, which can be exploited remotely. This can lead to the execution of arbitrary code via crafted ABC music files that trigger the overflows during translation into PostScript, potentially disrupting the confidentiality, integrity, and availability of protected information.
Recommendations For abcmidi version 20050101 and earlier, update to a version that contains a fix for this issue to prevent remote attackers from executing arbitrary code. As a temporary workaround, consider restricting the use of the abcmidi-yaps translator until a patch is available. Avoid using the abcmidi package with untrusted ABC music files until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03559
BDU:2015-03560
CVE-2006-1514
DSA-1043-1

Affected Products

Abcmidi