PT-2011-1401 · Abcm2Ps+1 · Abcm2Ps+1

Published

2011-02-18

·

Updated

2020-08-14

·

CVE-2010-3441

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions abcm2ps versions prior to 5.9.12
Description The issue is related to multiple buffer overflows that could allow remote attackers to execute arbitrary code. This can be achieved through a crafted input file related to the PUT0 and PUT1 output macros, or a crafted input file related to the trim title function. Additionally, a long -O option on a command line might also be a potential attack vector.
Recommendations For versions prior to 5.9.12, update to version 5.9.12 or later to resolve the issue. As a temporary workaround, consider restricting the use of the PUT0 and PUT1 output macros, and the trim title function, until a patch is available. Avoid using long -O options on the command line until the issue is resolved.

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2245
CVE-2010-3441

Affected Products

Alt Linux
Abcm2Ps