cbcvebase.
CVE-2019-1010060
published 2019-07-16

CVE-2019-1010060: NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed…

PriorityP356critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
7.17%
93.6th percentile
NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is: remote unauthenticated attacker. The fixed version is: 3.43. NOTE: this CVE refers to the issues not covered by CVE-2018-3846, CVE-2018-3847, CVE-2018-3848, and CVE-2018-3849. One example is ftp_status in drvrnet.c mishandling a long string beginning with a '4' character.

Affected

6 ranges
VendorProductVersion rangeFixed in
debiancfitsio< cfitsio 3.430-1 (bookworm)cfitsio 3.430-1 (bookworm)
nasacfitsio< 3.433.43
nasacfitsio>= 0 < 3.430-13.430-1
nasacfitsio>= 0 < 3.430-13.430-1
nasacfitsio>= 0 < 3.430-13.430-1
nasacfitsio>= 0 < 3.430-13.430-1

Detection & IOCsextracted from sources · hover to see the quote

pathdrvrnet.c
urlhttps://heasarc.gsfc.nasa.gov/FTP/software/fitsio/c/cfitsio3420.tar.gz
urlhttps://heasarc.gsfc.nasa.gov/FTP/software/fitsio/c/cfitsio3430.tar.gz
  • The vulnerable function `ftp_status` in `drvrnet.c` mishandles a long string beginning with a '4' character — monitor or fuzz FTP response parsing in CFITSIO for oversized strings starting with '4' (e.g., 4xx FTP error codes).
  • The attack vector is a remote unauthenticated attacker — network-accessible CFITSIO instances processing remote FITS files (e.g., via FTP URLs) should be treated as exposed attack surface.
  • Over 40 source code files were changed in the fix — any CFITSIO version prior to 3.43 across a wide range of components should be considered vulnerable, not just drvrnet.c.
  • ·This CVE explicitly excludes issues already covered by CVE-2018-3846, CVE-2018-3847, CVE-2018-3848, and CVE-2018-3849 — detections must account for the distinct, additional buffer overflows introduced here.
  • ·Fedora 32 and 33 ship cfitsio 3.470 and are not affected; only versions strictly prior to 3.43 are vulnerable.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.