CVE-2021-3410
published 2021-02-23CVE-2021-3410: A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.56%
43.2th percentile
A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cacalabs | libcaca | <= 0.99.beta20 | — |
| debian | debian_linux | — | — |
| debian | libcaca | < libcaca 0.99.beta19-2.2 (bookworm) | libcaca 0.99.beta19-2.2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libcaca_project | libcaca | — | — |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2.2 | 0.99.beta19-2.2 |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2.2 | 0.99.beta19-2.2 |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2.2 | 0.99.beta19-2.2 |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2.2 | 0.99.beta19-2.2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9xcm-8x7r-552c: A flaw was found in libcaca v0
ghsa_unreviewed·2022-05-24
CVE-2021-3410 [HIGH] CWE-119 GHSA-9xcm-8x7r-552c: A flaw was found in libcaca v0
A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context.
OSV
CVE-2021-3410: A flaw was found in libcaca v0
osv·2021-02-23·CVSS 7.8
CVE-2021-3410 [HIGH] CVE-2021-3410: A flaw was found in libcaca v0
A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context.
Ubuntu
libcaca vulnerability
vendor_ubuntu·2021-04-20
CVE-2021-3410 libcaca vulnerability
Title: libcaca vulnerability
Summary: libcaca could be made to execute arbitrary code if it received a specially crafted
image.
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-3410: libcaca - A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize...
vendor_debian·2021·CVSS 7.8
CVE-2021-3410 [HIGH] CVE-2021-3410: libcaca - A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize...
A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context.
Scope: local
bookworm: resolved (fixed in 0.99.beta19-2.2)
bullseye: resolved (fixed in 0.99.beta19-2.2)
forky: resolved (fixed in 0.99.beta19-2.2)
sid: resolved (fixed in 0.99.beta19-2.2)
trixie: resolved (fixed in 0.99.beta19-2.2)
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1928437https://github.com/cacalabs/libcaca/issues/52https://lists.debian.org/debian-lts-announce/2021/03/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WFGYICNTMNDNMDDUV4G2RYFB5HNJCOV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PC7EGOEQ5C4OD66ZUJJIIYEXBTZOCMZX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZSBCRN6EGQJUVOSD4OEEQ6XORHEM2CUL/https://bugzilla.redhat.com/show_bug.cgi?id=1928437https://github.com/cacalabs/libcaca/issues/52https://lists.debian.org/debian-lts-announce/2021/03/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WFGYICNTMNDNMDDUV4G2RYFB5HNJCOV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PC7EGOEQ5C4OD66ZUJJIIYEXBTZOCMZX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZSBCRN6EGQJUVOSD4OEEQ6XORHEM2CUL/
2021-02-23
Published