CVE-2021-32436
published 2022-03-10CVE-2021-32436: An out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified…
PriorityP426medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
1.64%
73.8th percentile
An out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abcm2ps_project | abcm2ps | — | — |
| abcm2ps_project | abcm2ps | >= 0 < 8.14.13-1 | 8.14.13-1 |
| abcm2ps_project | abcm2ps | >= 0 < 8.14.13-1 | 8.14.13-1 |
| abcm2ps_project | abcm2ps | >= 0 < 8.14.13-1 | 8.14.13-1 |
| abcm2ps_project | abcm2ps | >= 0 < 7.8.9-1+deb9u1build0.18.04.1 | 7.8.9-1+deb9u1build0.18.04.1 |
| abcm2ps_project | abcm2ps | >= 0 < 7.8.9-1ubuntu0.16.04.1~esm1 | 7.8.9-1ubuntu0.16.04.1~esm1 |
| abcm2ps_project | abcm2ps | >= 0 < 8.14.6-0.1ubuntu0.1~esm1 | 8.14.6-0.1ubuntu0.1~esm1 |
| abcm2ps_project | abcm2ps | >= 0 < 8.14.11-0.1ubuntu0.1~esm1 | 8.14.11-0.1ubuntu0.1~esm1 |
| debian | abcm2ps | < abcm2ps 8.14.13-1 (bookworm) | abcm2ps 8.14.13-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian6.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
abcm2ps vulnerabilities
vendor_ubuntu·2023-03-16·CVSS 9.8
CVE-2021-32435 [CRITICAL] abcm2ps vulnerabilities
Title: abcm2ps vulnerabilities
Summary: Several security issues were fixed in abcm2ps.
It was discovered that abcm2ps incorrectly
handled memory when parsing specially crafted ABC files.
An attacker could use this issue to cause abcm2ps to crash,
leading to a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 16.04 ESM
and Ubuntu 18.04 LTS.
(CVE-2018-10753, CVE-2018-10771, CVE-2019-1010069)
Chiba of Topsec Alpha Lab discovered that abcm2ps incorrectly
handled memory when parsing specially crafted ABC files.
An attacker could use this issue to cause abcm2ps to crash,
leading to a denial of service.
(CVE-2021-32434, CVE-2021-32435, CVE-2021-32436)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-32436: abcm2ps - An out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.1...
vendor_debian·2021·CVSS 6.5
CVE-2021-32436 [MEDIUM] CVE-2021-32436: abcm2ps - An out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.1...
An out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 8.14.13-1)
bullseye: open
forky: resolved (fixed in 8.14.13-1)
sid: resolved (fixed in 8.14.13-1)
trixie: resolved (fixed in 8.14.13-1)
OSV
abcm2ps vulnerabilities
osv·2023-03-16·CVSS 9.8
CVE-2018-10753 [CRITICAL] abcm2ps vulnerabilities
abcm2ps vulnerabilities
It was discovered that abcm2ps incorrectly
handled memory when parsing specially crafted ABC files.
An attacker could use this issue to cause abcm2ps to crash,
leading to a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 16.04 ESM
and Ubuntu 18.04 LTS.
(CVE-2018-10753, CVE-2018-10771, CVE-2019-1010069)
Chiba of Topsec Alpha Lab discovered that abcm2ps incorrectly
handled memory when parsing specially crafted ABC files.
An attacker could use this issue to cause abcm2ps to crash,
leading to a denial of service.
(CVE-2021-32434, CVE-2021-32435, CVE-2021-32436)
GHSA
GHSA-5qvg-hqqx-46rj: An out-of-bounds read in the function write_title() in subs
ghsa_unreviewed·2022-03-11
CVE-2021-32436 [MEDIUM] CWE-125 GHSA-5qvg-hqqx-46rj: An out-of-bounds read in the function write_title() in subs
An out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors.
OSV
CVE-2021-32436: An out-of-bounds read in the function write_title() in subs
osv·2022-03-10·CVSS 6.5
CVE-2021-32436 [MEDIUM] CVE-2021-32436: An out-of-bounds read in the function write_title() in subs
An out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/leesavide/abcm2ps/commit/2f56e1179cab6affeb8afa9d6c324008fe40d8e3https://github.com/leesavide/abcm2ps/issues/85https://lists.debian.org/debian-lts-announce/2022/04/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6333SXWMES3K22DBAOAW34G6EU6WIJEY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EVGJH4HMXI3TWMHQJQCG3M7KSXJWJM7R/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YTF4FXCW22FFB5HNQO3GK3F4FFBLTZKE/https://github.com/leesavide/abcm2ps/commit/2f56e1179cab6affeb8afa9d6c324008fe40d8e3https://github.com/leesavide/abcm2ps/issues/85https://lists.debian.org/debian-lts-announce/2022/04/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6333SXWMES3K22DBAOAW34G6EU6WIJEY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EVGJH4HMXI3TWMHQJQCG3M7KSXJWJM7R/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YTF4FXCW22FFB5HNQO3GK3F4FFBLTZKE/
2022-03-10
Published