cbcvebase.
CVE-2010-3441
published 2011-02-18

CVE-2010-3441: Multiple buffer overflows in abcm2ps before 5.9.12 might allow remote attackers to execute arbitrary code via (1) a crafted input file, related to the PUT0 and…

PriorityP342high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.85%
92.4th percentile
Multiple buffer overflows in abcm2ps before 5.9.12 might allow remote attackers to execute arbitrary code via (1) a crafted input file, related to the PUT0 and PUT1 output macros; (2) a crafted input file, related to the trim_title function; and possibly (3) a long -O option on a command line.

Affected

14 ranges
VendorProductVersion rangeFixed in
abcm2ps_projectabcm2ps>= 0 < 5.9.22-15.9.22-1
abcm2ps_projectabcm2ps>= 0 < 5.9.13-0.15.9.13-0.1
abcm2ps_projectabcm2ps>= 0 < 5.9.22-15.9.22-1
abcm2ps_projectabcm2ps>= 0 < 5.9.13-0.15.9.13-0.1
abcm2ps_projectabcm2ps>= 0 < 5.9.22-15.9.22-1
abcm2ps_projectabcm2ps>= 0 < 5.9.13-0.15.9.13-0.1
abcm2ps_projectabcm2ps>= 0 < 5.9.22-15.9.22-1
abcm2ps_projectabcm2ps>= 0 < 5.9.13-0.15.9.13-0.1
debianabcm2ps< abcm2ps 5.9.13-0.1 (bookworm)abcm2ps 5.9.13-0.1 (bookworm)
debianabcm2ps< abcm2ps 5.9.22-1 (bookworm)abcm2ps 5.9.22-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
moinejfabcm2ps< 5.9.135.9.13
moinejfabcm2ps< 5.9.125.9.12

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.