#VU45314 Heap-based buffer overflow in abcm2ps - CVE-2010-4743
Published: February 18, 2011 / Updated: December 5, 2020
abcm2ps
Lee S.
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing data within the getarena function in abc2ps.c in abcm2ps before 5.9.13 might allow remote attackers to execute arbitrary code via a crafted ABC file. A remote attacker can pass a specially crafted file to the affected application, trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
External links
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=577014
- http://lists.fedoraproject.org/pipermail/package-announce/2011-February/054015.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/054424.html
- http://moinejf.free.fr/abcm2ps-5.txt
- http://secunia.com/advisories/40033
- http://secunia.com/advisories/43338
- http://www.vupen.com/english/advisories/2011/0390
- https://bugzilla.redhat.com/show_bug.cgi?id=600729