cbcvebase.

Nasa Cfitsio vulnerabilities

5 known vulnerabilities affecting nasa/cfitsio.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4

Vulnerabilities

Page 1 of 1
CVE-2019-1010060P3CRITICALCVSS 9.8fixed in 3.432019-07-16
CVE-2019-1010060 [CRITICAL] CVE-2019-1010060: NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is: remote unauthenticated attacker. The fixed version is: 3.43. NOTE: this CVE refers to the issues not covered by CVE-2018-3846, CVE-2018-3847, CVE-2018-3848, and CVE-2018-38
nvdosv
CVE-2018-3849P3HIGHCVSS 8.8fixed in 3.4902018-04-16
CVE-2018-3849 [HIGH] CWE-787 CVE-2018-3849: In the ffghtb function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cau In the ffghtb function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.
nvdosv
CVE-2018-3848P3HIGHCVSS 8.8fixed in 3.4902018-04-16
CVE-2018-3848 [HIGH] CWE-787 CVE-2018-3848: In the ffghbn function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cau In the ffghbn function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.
nvdosv
CVE-2018-3846P3HIGHCVSS 8.8v3.42fixed in 3.43 [fixed: 3.43]2018-04-16
CVE-2018-3846 [HIGH] CWE-787 CVE-2018-3846: In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the lib In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.
nvdosv
CVE-2018-3847P3HIGHCVSS 8.8v3.422018-08-01
CVE-2018-3847 [HIGH] CWE-787 CVE-2018-3847: Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFI Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version 3.42. Specially crafted images parsed via the library, can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.
nvdosv
Nasa Cfitsio vulnerabilities | cvebase