CVE-2018-3847
published 2018-08-01CVE-2018-3847: Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version 3.42. Specially crafted images parsed…
PriorityP348high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.84%
85.2th percentile
Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version 3.42. Specially crafted images parsed via the library, can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cfitsio | < cfitsio 3.430-1 (bookworm) | cfitsio 3.430-1 (bookworm) |
| nasa | cfitsio | < 3.43 | 3.43 |
| nasa | cfitsio | — | — |
| nasa | cfitsio | >= 0 < 3.430-1 | 3.430-1 |
| nasa | cfitsio | >= 0 < 3.430-1 | 3.430-1 |
| nasa | cfitsio | >= 0 < 3.430-1 | 3.430-1 |
| nasa | cfitsio | >= 0 < 3.430-1 | 3.430-1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2019-1010060: cfitsio - NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbit...
vendor_debian·2019·CVSS 8.8
CVE-2019-1010060 [HIGH] CVE-2019-1010060: cfitsio - NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbit...
NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is: remote unauthenticated attacker. The fixed version is: 3.43. NOTE: this CVE refers to the issues not covered by CVE-2018-3846, CVE-2018-3847, CVE-2018-3848, and CVE-2018-3849. One example is ftp_status in drvrnet.c mishandling a long string beginning with a '4' character.
Scope: local
bookworm: resolved (fixed in 3.430-1)
bullseye: resolved (fixed in 3.430-1)
forky: resolved (fixed in 3.430-1)
sid: resolved (fixed in 3.430-1)
trixie: resolved (fixed in 3.430-1)
Debian
CVE-2018-3847: cfitsio - Multiple exploitable buffer overflow vulnerabilities exist in image parsing func...
vendor_debian·2018·CVSS 8.8
CVE-2018-3847 [HIGH] CVE-2018-3847: cfitsio - Multiple exploitable buffer overflow vulnerabilities exist in image parsing func...
Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version 3.42. Specially crafted images parsed via the library, can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.
Scope: local
bookworm: resolved (fixed in 3.430-1)
bullseye: resolved (fixed in 3.430-1)
forky: resolved (fixed in 3.430-1)
sid: resolved (fixed in 3.430-1)
trixie: resolved (fixed in 3.430-1)
GHSA
GHSA-3gpw-r459-56f2: NASA CFITSIO prior to 3
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2019-1010060 [HIGH] CWE-119 GHSA-3gpw-r459-56f2: NASA CFITSIO prior to 3
NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is: remote unauthenticated attacker. The fixed version is: 3.43. NOTE: this CVE refers to the issues not covered by CVE-2018-3846, CVE-2018-3847, CVE-2018-3848, and CVE-2018-3849. One example is ftp_status in drvrnet.c mishandling a long string beginning with a '4' character.
GHSA
GHSA-962f-cm8q-5q3r: Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version 3
ghsa_unreviewed·2022-05-13
CVE-2018-3847 [HIGH] CWE-787 GHSA-962f-cm8q-5q3r: Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version 3
Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version 3.42. Specially crafted images parsed via the library, can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.
OSV
CVE-2019-1010060: NASA CFITSIO prior to 3
osv·2019-07-16·CVSS 8.8
CVE-2019-1010060 [HIGH] CVE-2019-1010060: NASA CFITSIO prior to 3
NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is: remote unauthenticated attacker. The fixed version is: 3.43. NOTE: this CVE refers to the issues not covered by CVE-2018-3846, CVE-2018-3847, CVE-2018-3848, and CVE-2018-3849. One example is ftp_status in drvrnet.c mishandling a long string beginning with a '4' character.
OSV
linux-azure vulnerabilities
osv·2018-12-20·CVSS 7.8
CVE-2018-10902 linux-azure vulnerabilities
linux-azure vulnerabilities
USN-3847-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
kernel for Microsoft Azure Cloud systems for Ubuntu 14.04 LTS.
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-after-free vulnerability existed in the
Infiniband implementation in the
OSV
linux-hwe, linux-aws-hwe, linux-azure, linux-gcp vulnerabilities
osv·2018-12-20·CVSS 7.8
linux-hwe, linux-aws-hwe, linux-azure, linux-gcp vulnerabilities
linux-hwe, linux-aws-hwe, linux-azure, linux-gcp vulnerabilities
USN-3847-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
It was discovered that a race condition existed in the raw MIDI driver for
the Linux kernel, leading to a double free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2018-10902)
It was discovered that an integer overrun vulnerability existed in the
POSIX timers implementation in the Linux kernel. A local attacker could use
this to cause a denial of service. (CVE-2018-12896)
Noam Rathaus discovered that a use-after-free vulnerabili
OSV
CVE-2018-3847: Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version 3
osv·2018-08-01·CVSS 8.8
CVE-2018-3847 [HIGH] CVE-2018-3847: Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version 3
Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version 3.42. Specially crafted images parsed via the library, can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: TALOS-2018-0529-531 - Multiple Vulnerabilities in NASA CFITSIO library
blogs_talos·2018-04-12·CVSS 8.8
[HIGH] Vulnerability Spotlight: TALOS-2018-0529-531 - Multiple Vulnerabilities in NASA CFITSIO library
## Vulnerability Spotlight: TALOS-2018-0529-531 - Multiple Vulnerabilities in NASA CFITSIO library
Talos is disclosing three remote code execution vulnerabilities in the NASA CFITSIO library. CFITSIO is a library of C and Fortran subroutines for reading and writing data files in the Flexible Image Transport System (FITS) data format. FITS is a standard format endorsed by both NASA and the International Astronomical Union for astronomical data.
Specially crafted images parsed via the library can cause a stack-based buffer overflow, overwriting arbitrary data. An attacker can deliver a malicious FIT image to trigger this vulnerability, and potentially gain the ability to execute code.
Exploitable buffer overflow vulnerabilities exist in the image parsing functionality of the CFITSIO libra
Talos
Vulnerability Spotlight: TALOS-2018-0529-531 - Multiple Vulnerabilities in NASA CFITSIO library
blogs_talos·2018-04-12·CVSS 8.8
[HIGH] Vulnerability Spotlight: TALOS-2018-0529-531 - Multiple Vulnerabilities in NASA CFITSIO library
Talos is disclosing three remote code execution vulnerabilities in the NASA CFITSIO library. CFITSIO is a library of C and Fortran subroutines for reading and writing data files in the Flexible Image Transport System (FITS) data format. FITS is a standard format endorsed by both NASA and the International Astronomical Union for astronomical data.
Specially crafted images parsed via the library can cause a stack-based buffer overflow, overwriting arbitrary data. An attacker can deliver a malicious FIT image to trigger this vulnerability, and potentially gain the ability to execute code.
Exploitable buffer overflow vulnerabilities exist in the image parsing functionality of the CFITSIO library version 3.42.
The FIT file format stores image metadata in an ASCII header containing keyword-va
Bugzilla
CVE-2019-1010060 cfitsio: buffer overflow leads to arbitrary code execution
bugzilla·2020-06-25·CVSS 8.8
CVE-2019-1010060 [HIGH] CVE-2019-1010060 cfitsio: buffer overflow leads to arbitrary code execution
CVE-2019-1010060 cfitsio: buffer overflow leads to arbitrary code execution
NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is: remote unauthenticated attacker. The fixed version is: 3.43. NOTE: this CVE refers to the issues not covered by CVE-2018-3846, CVE-2018-3847, CVE-2018-3848, and CVE-2018-3849. One example is ftp_status in drvrnet.c mishandling a long string beginning with a '4' character.
Upstream pull request:
https://github.com/astropy/astropy/pull/7274
References:
https://heasarc.gsfc.nasa.gov/FTP/software/fitsio/c/cfitsio3420.tar.gz
https://heasarc.gsfc.nasa.gov/FTP/software/fitsio/c/cfitsio3430.tar.gz
https://heasarc.gsfc.nasa.gov/FTP/software/
2018-08-01
Published