Vulnerability Name: | CVE-2010-5325 (CCN-110606) | ||||||||||||||||
Assigned: | 2015-05-05 | ||||||||||||||||
Published: | 2015-05-05 | ||||||||||||||||
Updated: | 2019-12-27 | ||||||||||||||||
Summary: | Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via a long job title. | ||||||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-119 CWE-131 CWE-122 CWE-122 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: CONFIRM Type: Patch, Vendor Advisory http://bzr.linuxfoundation.org/loggerhead/openprinting/foomatic-4.0/foomatic-filters/annotate/head:/ChangeLog Source: MITRE Type: CNA CVE-2010-5325 Source: CCN Type: RHSA-2016-0491 Moderate: foomatic security update Source: REDHAT Type: Third Party Advisory RHSA-2016:0491 Source: CCN Type: oss-sec Mailing List, Mon, 15 Feb 2016 10:44:58 +0100 CVE request: foomatic-rip unhtmlify() buffer overflow vulnerability Source: CCN Type: oss-sec Mailing List, Mon, 15 Feb 2016 12:09:55 -0500 (EST) Re: CVE request: foomatic-rip unhtmlify() buffer overflow vulnerability Source: CCN Type: LinuxFoundation Web site Foomatic Source: MLIST Type: Third Party Advisory [oss-security] 20160215 CVE request: foomatic-rip unhtmlify() buffer overflow vulnerability Source: MLIST Type: Third Party Advisory [oss-security] 20160215 Re: CVE request: foomatic-rip unhtmlify() buffer overflow vulnerability Source: CONFIRM Type: Third Party Advisory http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html Source: CONFIRM Type: UNKNOWN https://bugs.linuxfoundation.org/show_bug.cgi?id=515 Source: CCN Type: Red Hat Bugzilla Bug 1218297 foomatic: potential remote arbitrary code execution Source: CONFIRM Type: Issue Tracking https://bugzilla.redhat.com/show_bug.cgi?id=1218297 Source: XF Type: UNKNOWN foomatic-cve20105325-bo(110606) Source: CCN Type: WhiteSource Vulnerability Database CVE-2010-5325 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |