PT-2010-1144 · Gnome+1 · Gmime+1
Jan Lieskovsky
·
Published
2010-02-08
·
Updated
2014-01-21
·
CVE-2010-0409
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GMime versions prior to 2.4.15
Gentoo Linux (affected versions not specified)
Description
The issue concerns a buffer overflow in the GMIME UUENCODE LEN macro, which can be exploited to cause a denial of service or possibly execute arbitrary code via input data for a uuencode operation. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely.
Recommendations
For GMime versions prior to 2.4.15, update to version 2.4.15 or later to resolve the issue.
As a temporary workaround, consider restricting input data for uuencode operations to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gmime
Gentoo Linux