PT-2010-1148 · Gnustep · Gnustep-Base

Dan Rosenberg

+1

·

Published

2010-05-12

·

Updated

2014-01-20

·

CVE-2010-1620

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GNUstep Base versions prior to 1.20.0 GNUstep Base versions prior to 1.20.1
Description The issue is related to an integer overflow in the load iface function in Tools/gdomap.c in gdomap, which might allow attackers to execute arbitrary code via a file or socket that provides configuration data with many entries, leading to a heap-based buffer overflow. Additionally, there are multiple vulnerabilities in the gnustep-base package that can lead to violations of confidentiality, integrity, and availability of protected information, and these can be exploited locally.
Recommendations For versions prior to 1.20.0, update to version 1.20.0 or later. For versions prior to 1.20.1, update to version 1.20.1 or later. As a temporary workaround, consider restricting access to the load iface function in Tools/gdomap.c until a patch is available.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09691
CVE-2010-1620

Affected Products

Gnustep-Base