CVE-2012-2091Improper Restriction of Operations within the Bounds of a Memory Buffer in Flightgear

Severity
9.3CRITICALNVD
EPSS
7.6%
top 8.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 17
Latest updateMay 17

Description

Multiple buffer overflows in FlightGear 2.6 and earlier and SimGear 2.6 and earlier allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long string in a rotor tag of an aircraft xml model to the Rotor::getValueforFGSet function in src/FDM/YASim/Rotor.cpp or (2) a crafted UDP packet to the SGSocketUDP::read function in simgear/simgear/simgear/io/sg_socket_udp.cxx.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages6 packages

debiandebian/simgear< flightgear 2.6.0-1.1 (bookworm)
Debiansimgear/simgear< 2.10.0-3+3
NVDsimgear/simgear2.6.0+2
debiandebian/flightgear< flightgear 2.6.0-1.1 (bookworm)
Debianflightgear/flightgear< 2.6.0-1.1+3

🔴Vulnerability Details

2
GHSA
GHSA-4p68-9fv9-q323: Multiple buffer overflows in FlightGear 22022-05-17
OSV
CVE-2012-2091: Multiple buffer overflows in FlightGear 22012-06-17

📋Vendor Advisories

1
Debian
CVE-2012-2091: flightgear - Multiple buffer overflows in FlightGear 2.6 and earlier and SimGear 2.6 and earl...2012

💬Community

2
Bugzilla
CVE-2012-2090 CVE-2012-2091 FlightGear various flaws [fedora-all]2012-04-11
Bugzilla
CVE-2012-2091 FlightGear: Stack-buffer overflow by retrieving crafted rotor name2012-04-11