CVE-2010-3441
published 2011-02-18CVE-2010-3441: Multiple buffer overflows in abcm2ps before 5.9.12 might allow remote attackers to execute arbitrary code via (1) a crafted input file, related to the PUT0 and…
PriorityP342high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.85%
92.4th percentile
Multiple buffer overflows in abcm2ps before 5.9.12 might allow remote attackers to execute arbitrary code via (1) a crafted input file, related to the PUT0 and PUT1 output macros; (2) a crafted input file, related to the trim_title function; and possibly (3) a long -O option on a command line.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abcm2ps_project | abcm2ps | >= 0 < 5.9.22-1 | 5.9.22-1 |
| abcm2ps_project | abcm2ps | >= 0 < 5.9.13-0.1 | 5.9.13-0.1 |
| abcm2ps_project | abcm2ps | >= 0 < 5.9.22-1 | 5.9.22-1 |
| abcm2ps_project | abcm2ps | >= 0 < 5.9.13-0.1 | 5.9.13-0.1 |
| abcm2ps_project | abcm2ps | >= 0 < 5.9.22-1 | 5.9.22-1 |
| abcm2ps_project | abcm2ps | >= 0 < 5.9.13-0.1 | 5.9.13-0.1 |
| abcm2ps_project | abcm2ps | >= 0 < 5.9.22-1 | 5.9.22-1 |
| abcm2ps_project | abcm2ps | >= 0 < 5.9.13-0.1 | 5.9.13-0.1 |
| debian | abcm2ps | < abcm2ps 5.9.13-0.1 (bookworm) | abcm2ps 5.9.13-0.1 (bookworm) |
| debian | abcm2ps | < abcm2ps 5.9.22-1 (bookworm) | abcm2ps 5.9.22-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| moinejf | abcm2ps | < 5.9.13 | 5.9.13 |
| moinejf | abcm2ps | < 5.9.12 | 5.9.12 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2010-3441: abcm2ps - Multiple buffer overflows in abcm2ps before 5.9.12 might allow remote attackers ...
vendor_debian·2010·CVSS 7.5
CVE-2010-3441 [HIGH] CVE-2010-3441: abcm2ps - Multiple buffer overflows in abcm2ps before 5.9.12 might allow remote attackers ...
Multiple buffer overflows in abcm2ps before 5.9.12 might allow remote attackers to execute arbitrary code via (1) a crafted input file, related to the PUT0 and PUT1 output macros; (2) a crafted input file, related to the trim_title function; and possibly (3) a long -O option on a command line.
Scope: local
bookworm: resolved (fixed in 5.9.13-0.1)
bullseye: resolved (fixed in 5.9.13-0.1)
forky: resolved (fixed in 5.9.13-0.1)
sid: resolved (fixed in 5.9.13-0.1)
trixie: resolved (fixed in 5.9.13-0.1)
Debian
CVE-2010-4744: abcm2ps - Multiple unspecified vulnerabilities in abcm2ps before 5.9.13 have unknown impac...
vendor_debian·2010·CVSS 7.5
CVE-2010-4744 [HIGH] CVE-2010-4744: abcm2ps - Multiple unspecified vulnerabilities in abcm2ps before 5.9.13 have unknown impac...
Multiple unspecified vulnerabilities in abcm2ps before 5.9.13 have unknown impact and attack vectors, a different issue than CVE-2010-3441.
Scope: local
bookworm: resolved (fixed in 5.9.22-1)
bullseye: resolved (fixed in 5.9.22-1)
forky: resolved (fixed in 5.9.22-1)
sid: resolved (fixed in 5.9.22-1)
trixie: resolved (fixed in 5.9.22-1)
Debian
CVE-2010-4743: abcm2ps - Heap-based buffer overflow in the getarena function in abc2ps.c in abcm2ps befor...
vendor_debian·2010·CVSS 7.5
CVE-2010-4743 [HIGH] CVE-2010-4743: abcm2ps - Heap-based buffer overflow in the getarena function in abc2ps.c in abcm2ps befor...
Heap-based buffer overflow in the getarena function in abc2ps.c in abcm2ps before 5.9.13 might allow remote attackers to execute arbitrary code via a crafted ABC file, a different vulnerability than CVE-2010-3441. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 5.9.22-1)
bullseye: resolved (fixed in 5.9.22-1)
forky: resolved (fixed in 5.9.22-1)
sid: resolved (fixed in 5.9.22-1)
trixie: resolved (fixed in 5.9.22-1)
GHSA
GHSA-hh8f-g344-97jg: Heap-based buffer overflow in the getarena function in abc2ps
ghsa_unreviewed·2022-05-13·CVSS 7.5
CVE-2010-4743 [HIGH] CWE-787 GHSA-hh8f-g344-97jg: Heap-based buffer overflow in the getarena function in abc2ps
Heap-based buffer overflow in the getarena function in abc2ps.c in abcm2ps before 5.9.13 might allow remote attackers to execute arbitrary code via a crafted ABC file, a different vulnerability than CVE-2010-3441. NOTE: some of these details are obtained from third party information.
GHSA
GHSA-w472-23r7-6hhp: Multiple buffer overflows in abcm2ps before 5
ghsa_unreviewed·2022-05-13
CVE-2010-3441 [HIGH] CWE-120 GHSA-w472-23r7-6hhp: Multiple buffer overflows in abcm2ps before 5
Multiple buffer overflows in abcm2ps before 5.9.12 might allow remote attackers to execute arbitrary code via (1) a crafted input file, related to the PUT0 and PUT1 output macros; (2) a crafted input file, related to the trim_title function; and possibly (3) a long -O option on a command line.
GHSA
GHSA-vp3v-x3r7-4vw2: Multiple unspecified vulnerabilities in abcm2ps before 5
ghsa_unreviewed·2022-05-13·CVSS 7.5
CVE-2010-4744 [HIGH] GHSA-vp3v-x3r7-4vw2: Multiple unspecified vulnerabilities in abcm2ps before 5
Multiple unspecified vulnerabilities in abcm2ps before 5.9.13 have unknown impact and attack vectors, a different issue than CVE-2010-3441.
OSV
CVE-2010-4743: Heap-based buffer overflow in the getarena function in abc2ps
osv·2011-02-18·CVSS 7.5
CVE-2010-4743 [HIGH] CVE-2010-4743: Heap-based buffer overflow in the getarena function in abc2ps
Heap-based buffer overflow in the getarena function in abc2ps.c in abcm2ps before 5.9.13 might allow remote attackers to execute arbitrary code via a crafted ABC file, a different vulnerability than CVE-2010-3441. NOTE: some of these details are obtained from third party information.
OSV
CVE-2010-3441: Multiple buffer overflows in abcm2ps before 5
osv·2011-02-18·CVSS 7.5
CVE-2010-3441 [HIGH] CVE-2010-3441: Multiple buffer overflows in abcm2ps before 5
Multiple buffer overflows in abcm2ps before 5.9.12 might allow remote attackers to execute arbitrary code via (1) a crafted input file, related to the PUT0 and PUT1 output macros; (2) a crafted input file, related to the trim_title function; and possibly (3) a long -O option on a command line.
OSV
CVE-2010-4744: Multiple unspecified vulnerabilities in abcm2ps before 5
osv·2011-02-18·CVSS 7.5
CVE-2010-4744 [HIGH] CVE-2010-4744: Multiple unspecified vulnerabilities in abcm2ps before 5
Multiple unspecified vulnerabilities in abcm2ps before 5.9.13 have unknown impact and attack vectors, a different issue than CVE-2010-3441.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3441 abcm2ps various flaws [fedora-all]
bugzilla·2010-12-16·CVSS 7.5
CVE-2010-3441 [HIGH] CVE-2010-3441 abcm2ps various flaws [fedora-all]
CVE-2010-3441 abcm2ps various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=580435
Please note: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2010-2053 emesene: symlink vulnerability allows overwriting arbitrary files
bugzilla·2010-06-07·CVSS 3.3
CVE-2010-2053 [LOW] CVE-2010-2053 emesene: symlink vulnerability allows overwriting arbitrary files
CVE-2010-2053 emesene: symlink vulnerability allows overwriting arbitrary files
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-2053 to
the following vulnerability:
Name: CVE-2010-2053
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2053
Assigned: 20100525
Reference: MLIST:[oss-security] 20100529 Fwd: emesene preditable temporary filename
Reference: URL: http://marc.info/?l=oss-security&m=127514641525366&w=2
Reference: CONFIRM: http://forum.emesene.org/index.php?topic=3441.0
Reference: CONFIRM: http://www.emesene.org/
Reference: OSVDB:65018
Reference: URL: http://osvdb.org/65018
Reference: SECUNIA:39945
Reference: URL: http://secunia.com/advisories/39945
Reference: XF:emesene-emsnpic-symlink(59045)
Reference: URL: http://xforce.iss.net/xforce/xfdb/59045
Bugzilla
CVE-2010-4743 CVE-2010-4744 Abcm2ps v5.9.13: Multiple security vulnerabilities
bugzilla·2010-06-05·CVSS 7.5
CVE-2010-4743 [HIGH] CVE-2010-4743 CVE-2010-4744 Abcm2ps v5.9.13: Multiple security vulnerabilities
CVE-2010-4743 CVE-2010-4744 Abcm2ps v5.9.13: Multiple security vulnerabilities
Abcm2ps upstream has released latest v5.9.13 version,
fixing "yet more multiple unspecified vulnerabilities":
[1] http://moinejf.free.fr/abcm2ps-5.txt
Current versions of abcm2ps package, present in Fedora release
of 11, 12, and 13, are v5.9.5 based (and potentially vulnerable).
Please rebase to new version to overcome these.
Discussion:
Created abcm2ps tracking bugs for this issue
Affects: fedora-all [bug 663809]
---
The CVE identifier of CVE-2010-4744 has been assigned to the following
vulnerability:
Multiple unspecified vulnerabilities in abcm2ps before 5.9.13 have
unknown impact and attack vectors, a different issue than
CVE-2010-3441.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=C
Bugzilla
CVE-2010-3441 Abcm2ps v5.9.12: Multiple unspecified security vulnerabilities
bugzilla·2010-04-08·CVSS 7.5
CVE-2010-3441 [HIGH] CVE-2010-3441 Abcm2ps v5.9.12: Multiple unspecified security vulnerabilities
CVE-2010-3441 Abcm2ps v5.9.12: Multiple unspecified security vulnerabilities
Abcm2ps upstream has released:
[1] http://moinejf.free.fr/
[2] http://moinejf.free.fr/abcm2ps-5.9.12.tar.gz
latest v5.9.12 version, addressing
"some security vulnerabilities"
[3] http://moinejf.free.fr/abcm2ps-5.txt
References:
[4] http://secunia.com/advisories/39345/
Requests for CVE(s) and further flaw(s) information:
[5] http://www.openwall.com/lists/oss-security/2010/04/08/5
[6] http://www.openwall.com/lists/oss-security/2010/04/08/6
Discussion:
This is CVE-2010-3441
---
Created abcm2ps tracking bugs for this issue
Affects: fedora-all [bug 663809]
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=577014http://lists.fedoraproject.org/pipermail/package-announce/2011-February/054015.htmlhttp://moinejf.free.fr/abcm2ps-5.txthttp://secunia.com/advisories/39345http://secunia.com/advisories/43338http://www.openwall.com/lists/oss-security/2010/04/08/5http://www.openwall.com/lists/oss-security/2010/04/08/6http://www.openwall.com/lists/oss-security/2010/04/08/7http://www.securityfocus.com/bid/39271http://www.vupen.com/english/advisories/2011/0390https://bugzilla.redhat.com/show_bug.cgi?id=580435http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=577014http://lists.fedoraproject.org/pipermail/package-announce/2011-February/054015.htmlhttp://moinejf.free.fr/abcm2ps-5.txthttp://secunia.com/advisories/39345http://secunia.com/advisories/43338http://www.openwall.com/lists/oss-security/2010/04/08/5http://www.openwall.com/lists/oss-security/2010/04/08/6http://www.openwall.com/lists/oss-security/2010/04/08/7http://www.securityfocus.com/bid/39271http://www.vupen.com/english/advisories/2011/0390https://bugzilla.redhat.com/show_bug.cgi?id=580435
2011-02-18
Published