PT-2010-1147 · Gnustep · Gnustep-Base

Dan Rosenberg

+1

·

Published

2010-05-12

·

Updated

2014-01-20

·

CVE-2010-1457

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions gnustep-base versions prior to 1.20.1
Description The issue concerns multiple vulnerabilities in the gnustep-base package that can lead to breaches in confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally. Specifically, a flaw in Tools/gdomap.c in gdomap in GNUstep Base before version 1.20.0 allows local users to read arbitrary files via certain options, which prints file contents in an error message.
Recommendations For versions prior to 1.20.1, update to version 1.20.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the gdomap tool until a patch is available.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09691
CVE-2010-1457

Affected Products

Gnustep-Base