CVE-2006-3145Off-by-one Error in Netpbm

4 documents4 sources
Severity
5.0MEDIUMNVD
EPSS
3.7%
top 11.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 22
Latest updateMay 1

Description

Buffer overflow in pamtofits of NetPBM 10.30 through 10.33 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code when assembling the header, possibly related to an off-by-one error.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDnetpbm/netpbm4 versions+3

Patches

🔴Vulnerability Details

1
GHSA
GHSA-gvx8-q9hp-2vcv: Buffer overflow in pamtofits of NetPBM 102022-05-01

📋Vendor Advisories

2
Debian
CVE-2006-3145: netpbm-free - Buffer overflow in pamtofits of NetPBM 10.30 through 10.33 allows remote attacke...2006
Red Hat
CVE-2006-3145: Buffer overflow in pamtofits of NetPBM 10