CVE Vulnerabilities

CVE-2010-1620

Published: May 12, 2010 | Modified: May 12, 2010
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Integer overflow in the load_iface function in Tools/gdomap.c in gdomap in GNUstep Base before 1.20.0 might allow context-dependent attackers to execute arbitrary code via a (1) file or (2) socket that provides configuration data with many entries, leading to a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Gnustep_base Gnustep * 1.19.3 (including)
Gnustep_base Gnustep 1.11.2 (including) 1.11.2 (including)
Gnustep_base Gnustep 1.12.0 (including) 1.12.0 (including)
Gnustep_base Gnustep 1.13.0 (including) 1.13.0 (including)
Gnustep_base Gnustep 1.14.0 (including) 1.14.0 (including)
Gnustep_base Gnustep 1.15.0 (including) 1.15.0 (including)
Gnustep_base Gnustep 1.15.1 (including) 1.15.1 (including)
Gnustep_base Gnustep 1.15.2 (including) 1.15.2 (including)
Gnustep_base Gnustep 1.15.4 (including) 1.15.4 (including)
Gnustep_base Gnustep 1.17.0 (including) 1.17.0 (including)
Gnustep_base Gnustep 1.18.0 (including) 1.18.0 (including)
Gnustep_base Gnustep 1.19.0 (including) 1.19.0 (including)
Gnustep_base Gnustep 1.19.1 (including) 1.19.1 (including)
Gnustep_base Gnustep 1.19.2 (including) 1.19.2 (including)
Gnustep-base Ubuntu dapper *
Gnustep-base Ubuntu hardy *
Gnustep-base Ubuntu jaunty *
Gnustep-base Ubuntu karmic *
Gnustep-base Ubuntu lucid *
Gnustep-base Ubuntu maverick *
Gnustep-base Ubuntu natty *
Gnustep-base Ubuntu oneiric *
Gnustep-base Ubuntu quantal *
Gnustep-base Ubuntu raring *
Gnustep-base Ubuntu saucy *
Gnustep-base Ubuntu upstream *
Gnustep-base Ubuntu utopic *
Gnustep-base Ubuntu vivid *
Gnustep-base Ubuntu wily *

References