CVE-2018-3846
published 2018-04-16CVE-2018-3846: In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting…
PriorityP349high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.07%
86.2th percentile
In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cfitsio | < cfitsio 3.430-1 (bookworm) | cfitsio 3.430-1 (bookworm) |
| fedoraproject | fedora | — | — |
| nasa | cfitsio | < 3.43 [fixed: 3.43] | 3.43 [fixed: 3.43] |
| nasa | cfitsio | < 3.43 | 3.43 |
| nasa | cfitsio | — | — |
| nasa | cfitsio | >= 0 < 3.430-1 | 3.430-1 |
| nasa | cfitsio | >= 0 < 3.430-1 | 3.430-1 |
| nasa | cfitsio | >= 0 < 3.430-1 | 3.430-1 |
| nasa | cfitsio | >= 0 < 3.430-1 | 3.430-1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2019-1010060: cfitsio - NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbit...
vendor_debian·2019·CVSS 8.8
CVE-2019-1010060 [HIGH] CVE-2019-1010060: cfitsio - NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbit...
NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is: remote unauthenticated attacker. The fixed version is: 3.43. NOTE: this CVE refers to the issues not covered by CVE-2018-3846, CVE-2018-3847, CVE-2018-3848, and CVE-2018-3849. One example is ftp_status in drvrnet.c mishandling a long string beginning with a '4' character.
Scope: local
bookworm: resolved (fixed in 3.430-1)
bullseye: resolved (fixed in 3.430-1)
forky: resolved (fixed in 3.430-1)
sid: resolved (fixed in 3.430-1)
trixie: resolved (fixed in 3.430-1)
Red Hat
cfitsio: Unsafe use of sprintf() can allow a remote unauthenticated attacker to execute arbitrary code
vendor_redhat·2018-03-10·CVSS 8.8
CVE-2018-3846 [HIGH] CWE-20 cfitsio: Unsafe use of sprintf() can allow a remote unauthenticated attacker to execute arbitrary code
cfitsio: Unsafe use of sprintf() can allow a remote unauthenticated attacker to execute arbitrary code
In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.
Package: cfitsio (Red Hat Enterprise Linux 8) - Will not fix
Package: cfitsio (Red Hat OpenShift Enterprise 2) - Will not fix
Debian
CVE-2018-3846: cfitsio - In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted image...
vendor_debian·2018·CVSS 8.8
CVE-2018-3846 [HIGH] CVE-2018-3846: cfitsio - In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted image...
In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.
Scope: local
bookworm: resolved (fixed in 3.430-1)
bullseye: resolved (fixed in 3.430-1)
forky: resolved (fixed in 3.430-1)
sid: resolved (fixed in 3.430-1)
trixie: resolved (fixed in 3.430-1)
GHSA
GHSA-3gpw-r459-56f2: NASA CFITSIO prior to 3
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2019-1010060 [HIGH] CWE-119 GHSA-3gpw-r459-56f2: NASA CFITSIO prior to 3
NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is: remote unauthenticated attacker. The fixed version is: 3.43. NOTE: this CVE refers to the issues not covered by CVE-2018-3846, CVE-2018-3847, CVE-2018-3848, and CVE-2018-3849. One example is ftp_status in drvrnet.c mishandling a long string beginning with a '4' character.
GHSA
GHSA-cr48-5q9g-m667: In the ffgphd and ffgtkn functions in NASA CFITSIO 3
ghsa_unreviewed·2022-05-13
CVE-2018-3846 [HIGH] CWE-787 GHSA-cr48-5q9g-m667: In the ffgphd and ffgtkn functions in NASA CFITSIO 3
In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.
OSV
CVE-2019-1010060: NASA CFITSIO prior to 3
osv·2019-07-16·CVSS 8.8
CVE-2019-1010060 [HIGH] CVE-2019-1010060: NASA CFITSIO prior to 3
NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is: remote unauthenticated attacker. The fixed version is: 3.43. NOTE: this CVE refers to the issues not covered by CVE-2018-3846, CVE-2018-3847, CVE-2018-3848, and CVE-2018-3849. One example is ftp_status in drvrnet.c mishandling a long string beginning with a '4' character.
OSV
CVE-2018-3846: In the ffgphd and ffgtkn functions in NASA CFITSIO 3
osv·2018-04-16·CVSS 8.8
CVE-2018-3846 [HIGH] CVE-2018-3846: In the ffgphd and ffgtkn functions in NASA CFITSIO 3
In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: TALOS-2018-0529-531 - Multiple Vulnerabilities in NASA CFITSIO library
blogs_talos·2018-04-12·CVSS 8.8
[HIGH] Vulnerability Spotlight: TALOS-2018-0529-531 - Multiple Vulnerabilities in NASA CFITSIO library
## Vulnerability Spotlight: TALOS-2018-0529-531 - Multiple Vulnerabilities in NASA CFITSIO library
Talos is disclosing three remote code execution vulnerabilities in the NASA CFITSIO library. CFITSIO is a library of C and Fortran subroutines for reading and writing data files in the Flexible Image Transport System (FITS) data format. FITS is a standard format endorsed by both NASA and the International Astronomical Union for astronomical data.
Specially crafted images parsed via the library can cause a stack-based buffer overflow, overwriting arbitrary data. An attacker can deliver a malicious FIT image to trigger this vulnerability, and potentially gain the ability to execute code.
Exploitable buffer overflow vulnerabilities exist in the image parsing functionality of the CFITSIO libra
Talos
Vulnerability Spotlight: TALOS-2018-0529-531 - Multiple Vulnerabilities in NASA CFITSIO library
blogs_talos·2018-04-12·CVSS 8.8
[HIGH] Vulnerability Spotlight: TALOS-2018-0529-531 - Multiple Vulnerabilities in NASA CFITSIO library
Talos is disclosing three remote code execution vulnerabilities in the NASA CFITSIO library. CFITSIO is a library of C and Fortran subroutines for reading and writing data files in the Flexible Image Transport System (FITS) data format. FITS is a standard format endorsed by both NASA and the International Astronomical Union for astronomical data.
Specially crafted images parsed via the library can cause a stack-based buffer overflow, overwriting arbitrary data. An attacker can deliver a malicious FIT image to trigger this vulnerability, and potentially gain the ability to execute code.
Exploitable buffer overflow vulnerabilities exist in the image parsing functionality of the CFITSIO library version 3.42.
The FIT file format stores image metadata in an ASCII header containing keyword-va
Bugzilla
CVE-2019-1010060 cfitsio: buffer overflow leads to arbitrary code execution
bugzilla·2020-06-25·CVSS 8.8
CVE-2019-1010060 [HIGH] CVE-2019-1010060 cfitsio: buffer overflow leads to arbitrary code execution
CVE-2019-1010060 cfitsio: buffer overflow leads to arbitrary code execution
NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is: remote unauthenticated attacker. The fixed version is: 3.43. NOTE: this CVE refers to the issues not covered by CVE-2018-3846, CVE-2018-3847, CVE-2018-3848, and CVE-2018-3849. One example is ftp_status in drvrnet.c mishandling a long string beginning with a '4' character.
Upstream pull request:
https://github.com/astropy/astropy/pull/7274
References:
https://heasarc.gsfc.nasa.gov/FTP/software/fitsio/c/cfitsio3420.tar.gz
https://heasarc.gsfc.nasa.gov/FTP/software/fitsio/c/cfitsio3430.tar.gz
https://heasarc.gsfc.nasa.gov/FTP/software/
Bugzilla
CVE-2018-3846 cfitsio: Unsafe use of sprintf() can allow a remote unauthenticated attacker to execute arbitrary code
bugzilla·2018-04-05·CVSS 8.8
CVE-2018-3846 [HIGH] CVE-2018-3846 cfitsio: Unsafe use of sprintf() can allow a remote unauthenticated attacker to execute arbitrary code
CVE-2018-3846 cfitsio: Unsafe use of sprintf() can allow a remote unauthenticated attacker to execute arbitrary code
CFITSIO before version 3.43 unsafely uses sprintf() in multiple files without checking input size. A remote unauthenticated attacker could exploit this to execute arbitrary code.
External References:
https://heasarc.gsfc.nasa.gov/FTP/software/fitsio/c/docs/changes2.txt
Additional References:
https://github.com/astropy/astropy/pull/7274
Discussion:
Created cfitsio tracking bugs for this issue:
Affects: fedora-all [bug 1563915]
Affects: epel-all [bug 1563916]
---
Openshift Enterprise 2 is out of support scope. Marking it as wont fix.
ref: https://access.redhat.com/support/policy/updates/openshift
---
The CVE-2018-1000166 is possibly a duplicate of CVE-2018-3846,
Bugzilla
CVE-2018-3846 cfitsio: Unsafe use of sprintf() can allow a remote unauthenticated attacker to execute arbitrary code [fedora-all]
bugzilla·2018-04-05·CVSS 8.8
CVE-2018-3846 [HIGH] CVE-2018-3846 cfitsio: Unsafe use of sprintf() can allow a remote unauthenticated attacker to execute arbitrary code [fedora-all]
CVE-2018-3846 cfitsio: Unsafe use of sprintf() can allow a remote unauthenticated attacker to execute arbitrary code [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2018-3846 cfitsio: Unsafe use of sprintf() can allow a remote unauthenticated attacker to execute arbitrary code [epel-all]
bugzilla·2018-04-05·CVSS 8.8
CVE-2018-3846 [HIGH] CVE-2018-3846 cfitsio: Unsafe use of sprintf() can allow a remote unauthenticated attacker to execute arbitrary code [epel-all]
CVE-2018-3846 cfitsio: Unsafe use of sprintf() can allow a remote unauthenticated attacker to execute arbitrary code [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K46I2MFPCEOGC5LLDXZSWPB3EBPON3KA/https://security.gentoo.org/glsa/202101-24https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0529https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K46I2MFPCEOGC5LLDXZSWPB3EBPON3KA/https://security.gentoo.org/glsa/202101-24https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0529
2018-04-16
Published