CVE-2010-4743: Buffer Overflow
Abcm2ps upstream has released latest v5.9.13 version, fixing "yet more multiple unspecified vulnerabilities": [1] http://moinejf.free.fr/abcm2ps-5.txt
Current versions of abcm2ps package, present in Fedora release of 11, 12, and 13, are v5.9.5 based (and potentially vulnerable).
Please rebase to new version to overcome these.
Other sources
Heap-based buffer overflow in the getarena function in abc2ps.c in abcm2ps before 5.9.13 might allow remote attackers to execute arbitrary code via a crafted ABC file, a different vulnerability than CVE-2010-3441. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4743?
CVE-2010-4743 has not been assigned a specific severity rating, but it is related to multiple unspecified vulnerabilities in abcm2ps.
How do I fix CVE-2010-4743?
To fix CVE-2010-4743, upgrade to abcm2ps version 5.9.13 or later.
Which versions of abcm2ps are affected by CVE-2010-4743?
CVE-2010-4743 affects abcm2ps versions prior to 5.9.13.
Is there a patch for CVE-2010-4743?
A patch for CVE-2010-4743 is included in the latest version 5.9.13 of abcm2ps.
What systems are impacted by CVE-2010-4743?
CVE-2010-4743 impacts Fedora versions 11, 12, and 13 that utilize abcm2ps versions before 5.9.13.