CVE-2018-10753
published 2018-05-05CVE-2018-10753: Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service…
PriorityP338critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.75%
84.7th percentile
Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abcm2ps_project | abcm2ps | >= 0 < 8.14.2-0.1 | 8.14.2-0.1 |
| abcm2ps_project | abcm2ps | >= 0 < 8.14.2-0.1 | 8.14.2-0.1 |
| abcm2ps_project | abcm2ps | >= 0 < 8.14.2-0.1 | 8.14.2-0.1 |
| abcm2ps_project | abcm2ps | >= 0 < 8.14.2-0.1 | 8.14.2-0.1 |
| abcm2ps_project | abcm2ps | >= 0 < 7.8.9-1+deb9u1build0.18.04.1 | 7.8.9-1+deb9u1build0.18.04.1 |
| abcm2ps_project | abcm2ps | >= 0 < 7.8.9-1ubuntu0.16.04.1~esm1 | 7.8.9-1ubuntu0.16.04.1~esm1 |
| abcm2ps_project | abcm2ps | >= 0 < 8.14.6-0.1ubuntu0.1~esm1 | 8.14.6-0.1ubuntu0.1~esm1 |
| abcm2ps_project | abcm2ps | >= 0 < 8.14.11-0.1ubuntu0.1~esm1 | 8.14.11-0.1ubuntu0.1~esm1 |
| debian | abcm2ps | < abcm2ps 8.14.2-0.1 (bookworm) | abcm2ps 8.14.2-0.1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| linuxfoundation | ceph | >= 0 < 15.2.7-0ubuntu0.20.04.2 | 15.2.7-0ubuntu0.20.04.2 |
| moinejf | abcm2ps | <= 8.13.20 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
abcm2ps vulnerabilities
vendor_ubuntu·2023-03-16·CVSS 9.8
CVE-2021-32435 [CRITICAL] abcm2ps vulnerabilities
Title: abcm2ps vulnerabilities
Summary: Several security issues were fixed in abcm2ps.
It was discovered that abcm2ps incorrectly
handled memory when parsing specially crafted ABC files.
An attacker could use this issue to cause abcm2ps to crash,
leading to a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 16.04 ESM
and Ubuntu 18.04 LTS.
(CVE-2018-10753, CVE-2018-10771, CVE-2019-1010069)
Chiba of Topsec Alpha Lab discovered that abcm2ps incorrectly
handled memory when parsing specially crafted ABC files.
An attacker could use this issue to cause abcm2ps to crash,
leading to a denial of service.
(CVE-2021-32434, CVE-2021-32435, CVE-2021-32436)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2018-10753: abcm2ps - Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps...
vendor_debian·2018·CVSS 9.8
CVE-2018-10753 [CRITICAL] CVE-2018-10753: abcm2ps - Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps...
Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
Scope: local
bookworm: resolved (fixed in 8.14.2-0.1)
bullseye: resolved (fixed in 8.14.2-0.1)
forky: resolved (fixed in 8.14.2-0.1)
sid: resolved (fixed in 8.14.2-0.1)
trixie: resolved (fixed in 8.14.2-0.1)
OSV
abcm2ps vulnerabilities
osv·2023-03-16·CVSS 9.8
CVE-2018-10753 [CRITICAL] abcm2ps vulnerabilities
abcm2ps vulnerabilities
It was discovered that abcm2ps incorrectly
handled memory when parsing specially crafted ABC files.
An attacker could use this issue to cause abcm2ps to crash,
leading to a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 16.04 ESM
and Ubuntu 18.04 LTS.
(CVE-2018-10753, CVE-2018-10771, CVE-2019-1010069)
Chiba of Topsec Alpha Lab discovered that abcm2ps incorrectly
handled memory when parsing specially crafted ABC files.
An attacker could use this issue to cause abcm2ps to crash,
leading to a denial of service.
(CVE-2021-32434, CVE-2021-32435, CVE-2021-32436)
GHSA
GHSA-wwg9-xxwx-gj49: Stack-based buffer overflow in the delayed_output function in music
ghsa_unreviewed·2022-05-13
CVE-2018-10753 [CRITICAL] CWE-787 GHSA-wwg9-xxwx-gj49: Stack-based buffer overflow in the delayed_output function in music
Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
OSV
ceph vulnerabilities
osv·2021-01-28·CVSS 7.5
CVE-2020-10736 ceph vulnerabilities
ceph vulnerabilities
Olle Segerdahl found that ceph-mon and ceph-mgr daemons did not properly
restrict access, resulting in gaining access to unauthorized resources. An
authenticated user could use this vulnerability to modify the configuration and
possibly conduct further attacks. (CVE-2020-10736)
Adam Mohammed found that Ceph Object Gateway was vulnerable to HTTP header
injection via a CORS ExposeHeader tag. An attacker could use this to gain access
or cause a crash. (CVE-2020-10753)
Ilya Dryomov found that Cephx authentication did not verify Ceph clients
correctly and was then vulnerable to replay attacks in Nautilus. An attacker
could use the Ceph cluster network to authenticate via a packet sniffer and
perform actions. This issue is a reintroduction of CVE-2018-1128.
(CVE-2020-2566
OSV
CVE-2018-10753: Stack-based buffer overflow in the delayed_output function in music
osv·2018-05-05·CVSS 9.8
CVE-2018-10753 [CRITICAL] CVE-2018-10753: Stack-based buffer overflow in the delayed_output function in music
Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10753 abcm2ps: stack based buffer overflow in the delayed_output function in music.c
bugzilla·2018-05-08·CVSS 9.8
CVE-2018-10753 [CRITICAL] CVE-2018-10753 abcm2ps: stack based buffer overflow in the delayed_output function in music.c
CVE-2018-10753 abcm2ps: stack based buffer overflow in the delayed_output function in music.c
A flaw was found in abcm2ps through 8.13.20. A stack based buffer overflow in the delayed_output function in music.c allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
References:
https://github.com/leesavide/abcm2ps/issues/16
Discussion:
Created abcm2ps tracking bugs for this issue:
Affects: fedora-all [bug 1576118]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
Bugzilla
CVE-2018-10753 abcm2ps: stack based buffer overflow in the delayed_output function in music.c [fedora-all]
bugzilla·2018-05-08·CVSS 9.8
CVE-2018-10753 [CRITICAL] CVE-2018-10753 abcm2ps: stack based buffer overflow in the delayed_output function in music.c [fedora-all]
CVE-2018-10753 abcm2ps: stack based buffer overflow in the delayed_output function in music.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
https://drive.google.com/drive/u/2/folders/1DvBEh5D-eW4UkvX3947UQh62i7hUIFN1https://github.com/leesavide/abcm2ps/issues/16https://lists.debian.org/debian-lts-announce/2022/04/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IGDXW2I3MY3QH4PJXLJET5QZZXMXTNWO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LSTB65NYYCKU7O6RF5B6CYY5IA6CA66Y/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W6DUTXB4EC3TQHTTAAIBKJ54GJTF6Y7V/https://drive.google.com/drive/u/2/folders/1DvBEh5D-eW4UkvX3947UQh62i7hUIFN1https://github.com/leesavide/abcm2ps/issues/16https://lists.debian.org/debian-lts-announce/2022/04/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IGDXW2I3MY3QH4PJXLJET5QZZXMXTNWO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LSTB65NYYCKU7O6RF5B6CYY5IA6CA66Y/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W6DUTXB4EC3TQHTTAAIBKJ54GJTF6Y7V/
2018-05-05
Published