CVE-2018-10753Out-of-bounds Write in Abcm2ps

Severity
9.8CRITICALNVD
OSV7.5
EPSS
1.9%
top 16.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 5
Latest updateMar 16

Description

Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

debiandebian/abcm2ps< abcm2ps 8.14.2-0.1 (bookworm)
Debianabcm2ps_project/abcm2ps< 8.14.2-0.1+3
Ubuntuabcm2ps_project/abcm2ps< 7.8.9-1+deb9u1build0.18.04.1+3
NVDmoinejf/abcm2ps8.13.20
Ubuntulinuxfoundation/ceph< 15.2.7-0ubuntu0.20.04.2

Also affects: Debian Linux 9.0, Fedora 30, 31, 32

🔴Vulnerability Details

4
OSV
abcm2ps vulnerabilities2023-03-16
GHSA
GHSA-wwg9-xxwx-gj49: Stack-based buffer overflow in the delayed_output function in music2022-05-13
OSV
ceph vulnerabilities2021-01-28
OSV
CVE-2018-10753: Stack-based buffer overflow in the delayed_output function in music2018-05-05

📋Vendor Advisories

2
Ubuntu
abcm2ps vulnerabilities2023-03-16
Debian
CVE-2018-10753: abcm2ps - Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps...2018

💬Community

2
Bugzilla
CVE-2018-10753 abcm2ps: stack based buffer overflow in the delayed_output function in music.c2018-05-08
Bugzilla
CVE-2018-10753 abcm2ps: stack based buffer overflow in the delayed_output function in music.c [fedora-all]2018-05-08