Gentoo Archives: gentoo-announce

From: Alex Legler <a3li@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 201111-12 ] abcm2ps: Multiple vulnerabilities
Date: Sun, 20 Nov 2011 18:30:25
Message-Id: 201111201915.07686.a3li@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201111-12
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: abcm2ps: Multiple vulnerabilities
9 Date: November 20, 2011
10 Bugs: #322859
11 ID: 201111-12
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities, including buffer overflows, have been found
19 in abcm2ps.
20
21 Background
22 ==========
23
24 abcm2ps is a program to convert abc files to Postscript files.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 media-sound/abcm2ps < 5.9.13 >= 5.9.13
33
34 Description
35 ===========
36
37 Multiple vulnerabilities have been discovered in abcm2ps:
38
39 * Boundary errors in the PUT0 and PUT1 macros, the trim_title()
40 function, or a long "-O" command line option can lead to a buffer
41 overflow (CVE-2010-3441).
42 * A vulnerability in the getarena() function in abc2ps.c can cause a
43 heap-based buffer overflow in abcm2ps (CVE-2010-4743).
44 * Multiple unspecified vulnerabilities (CVE-2010-4744).
45
46 Impact
47 ======
48
49 A remote attacker could entice a user to load a specially crafted ABC
50 file or use a long -O option on the command line, resulting in the
51 execution of arbitrary code.
52
53 Workaround
54 ==========
55
56 There is no known workaround at this time.
57
58 Resolution
59 ==========
60
61 All abcm2ps users should upgrade to the latest stable version:
62
63 # emerge --sync
64 # emerge --ask --oneshot --verbose ">=media-sound/abcm2ps-5.9.13"
65
66 NOTE: This is a legacy GLSA. Updates for all affected architectures are
67 available since August 27, 2010. It is likely that your system is
68 already no longer affected by this issue.
69
70 References
71 ==========
72
73 [ 1 ] CVE-2010-3441
74 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3441
75 [ 2 ] CVE-2010-4743
76 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4743
77 [ 3 ] CVE-2010-4744
78 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4744
79
80 Availability
81 ============
82
83 This GLSA and any updates to it are available for viewing at
84 the Gentoo Security Website:
85
86 http://security.gentoo.org/glsa/glsa-201111-12.xml
87
88 Concerns?
89 =========
90
91 Security is a primary focus of Gentoo Linux and ensuring the
92 confidentiality and security of our users' machines is of utmost
93 importance to us. Any security concerns should be addressed to
94 security@g.o or alternatively, you may file a bug at
95 https://bugs.gentoo.org.
96
97 License
98 =======
99
100 Copyright 2011 Gentoo Foundation, Inc; referenced text
101 belongs to its owner(s).
102
103 The contents of this document are licensed under the
104 Creative Commons - Attribution / Share Alike license.
105
106 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature