The giftrans function in giftrans 1.12.2 contains a stack-based buffer overflow because a value inside the input file determines the amount of data to write. This allows an attacker to overwrite up to 250 bytes outside of the allocated buffer with arbitrary data.
References
Link | Resource |
---|---|
http://web.archive.org/web/20150801185019/ | Broken Link |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1002739 | Exploit Mailing List Third Party Advisory |
https://www.abdn.ac.uk/tools/ibmpc/giftrans/index.hti | Broken Link |
Configurations
History
08 Aug 2023, 14:21
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-1284 |
10 Jan 2022, 21:31
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1002739 - Exploit, Mailing List, Third Party Advisory | |
References | (MISC) http://web.archive.org/web/20150801185019/ - Broken Link | |
References | (MISC) https://www.abdn.ac.uk/tools/ibmpc/giftrans/index.hti - Broken Link | |
CPE | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* cpe:2.3:a:giftrans_project:giftrans:1.12.2:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
|
CWE | CWE-787 | |
CVSS |
v2 : v3 : |
v2 : 5.8
v3 : 7.1 |
01 Jan 2022, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-01-01 21:15
Updated : 2024-02-04 22:08
NVD link : CVE-2021-45972
Mitre link : CVE-2021-45972
CVE.ORG link : CVE-2021-45972
JSON object : View
Products Affected
debian
- debian_linux
giftrans_project
- giftrans
CWE
CWE-1284
Improper Validation of Specified Quantity in Input