Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 9 Stretch: DLA-2983-1 Critical: abcm2ps Denial of Service

debian lts
Calendar Grey April 17, 2022
Dist Debian Esm H88
Numerous security flaws in xyztool necessitate immediate patches to avert possible system failures and exploitation attempts.
Multiple vulnerabilities have been discovered in abcm2ps: program which translates ABC music description files to PostScript

Summary

Multiple vulnerabilities have been discovered in abcm2ps: program which
translates ABC music description files to PostScript.

CVE-2018-10753

Stack-based buffer overflow in the delayed_output function in music.c
allows remote attackers to cause a denial of service (application crash) or
possibly have unspecified other impact.

CVE-2018-10771

Stack-based buffer overflow in the get_key function in parse.c allows remote
attackers to cause a denial of service (application crash) or possibly have
unspecified other impact.

CVE-2019-1010069

Incorrect access control allows attackers to cause a denial of service via a
crafted file.

CVE-2021-32434

Array overflow when wrong duration in voice overlay.

CVE-2021-32435

Stack-based buffer overflow in the function get_key in parse.c allows remote
attackers to cause a senial of service (DoS) via unspecified vectors.

CVE-2021-32436

Out-of-bounds read in the function write_title() in subs.c allows remote

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: abcm2ps
Version: 7.8.9-1+deb9u1
CVE ID: CVE-2018-10753 CVE-2018-10771 CVE-2019-1010069 CVE-2021-32434

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here