CVE-2011-0200
published 2011-06-24CVE-2011-0200: Integer overflow in ColorSync in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application…
PriorityP433medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.90%
89.2th percentile
Integer overflow in ColorSync in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image containing a crafted embedded ColorSync profile that triggers a heap-based buffer overflow.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat1.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6c88-gv2x-2fhc: Integer overflow in ColorSync in Apple Mac OS X before 10
ghsa_unreviewed·2022-05-17
CVE-2011-0200 [MEDIUM] GHSA-6c88-gv2x-2fhc: Integer overflow in ColorSync in Apple Mac OS X before 10
Integer overflow in ColorSync in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image containing a crafted embedded ColorSync profile that triggers a heap-based buffer overflow.
Red Hat
hplip: insecure temporary file handling flaws
vendor_redhat·2013-02-21·CVSS 1.2
CVE-2013-0200 [LOW] CWE-377 hplip: insecure temporary file handling flaws
hplip: insecure temporary file handling flaws
HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.
Statement: This issue does not affect the version of hplip and hplip3 as shipped with Red Hat Enterprise Linux 5. This issue has been addressed in Red Hat Enterprise Linux 6 via RHSA-2013:0500.
Package: hplip (Red Hat Enterprise Linux 5) - Not affected
Package: hplip3 (Red Hat Enterprise Linux 5) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0200 hplip: insecure temporary file handling flaws
bugzilla·2013-01-21·CVSS 1.2
CVE-2013-0200 [LOW] CVE-2013-0200 hplip: insecure temporary file handling flaws
CVE-2013-0200 hplip: insecure temporary file handling flaws
Temporary file handling flaws were found in several places in hplip. Because a predicatable temporary filenames are used, an attacker could use a symlink attack to overwrite an arbitrary file with the privileges of the process running hplip.
This is a different flaw than CVE-2011-2722.
Discussion:
Acknowledgements:
This issue was discovered by Tim Waugh of Red Hat.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0500 https://rhn.redhat.com/errata/RHSA-2013-0500.html
---
Statement:
This issue does not affect the version of hplip and hplip3 as shipped with Red Hat Enterprise Linux 5. This issue has been addressed in Red Hat Enterprise Linux 6 via RHSA-2013:0500.
Bugzilla
CVE-2006-1168 busybox: uncompress buffer underflow
bugzilla·2011-08-05·CVSS 7.5
CVE-2006-1168 [HIGH] CVE-2006-1168 busybox: uncompress buffer underflow
CVE-2006-1168 busybox: uncompress buffer underflow
Description of problem:
busybox embeds (n)compress code in its libunarchive/libarchive. This embedded copy has not been patched for the following bug:
https://bugs.gentoo.org/show_bug.cgi?id=141728
http://ncompress.git.sourceforge.net/git/gitweb.cgi?p=ncompress/ncompress;a=commitdiff;h=e21aad4a5a3ba0b6c2279b28a80f85b0b226a175
Steps to Reproduce:
$ perl -e 'print "\x1f\x9d\x90","\x01"x"2048"' | busybox uncompress
Segmentation fault
Discussion:
bss or heap, depending on the version, it seems.
---
Fixed in upstream git:
commit 251fc70e9722f931eec23a34030d05ba5f747b0e
Author: Denys Vlasenko
Date: Thu Aug 18 14:29:41 2011 +0200
uncompress: fix buffer underrun by corrupted input
Fix for the latest release:
http://busybox.net/download
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2011//Jul/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2011//Jun/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2012/Feb/msg00000.htmlhttp://support.apple.com/kb/HT4723http://support.apple.com/kb/HT4808http://support.apple.com/kb/HT4981http://support.apple.com/kb/HT5130http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2011//Jul/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2011//Jun/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2012/Feb/msg00000.htmlhttp://support.apple.com/kb/HT4723http://support.apple.com/kb/HT4808http://support.apple.com/kb/HT4981http://support.apple.com/kb/HT5130
2011-06-24
Published