HIGH
Heap-based buffer overflow in the HX_split function in string.c in libHX before 3.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a string that is inconsistent with the expected number of fields
Published Aug 24, 2010
10.0
HIGHCVSS 2.0
EPSS 5.51%
Description
Heap-based buffer overflow in the HX_split function in string.c in libHX before 3.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a string that is inconsistent with the expected number of fields.
Affected products
No data.
OR
- ≤ 3.5
- 1.10.0
- 1.10.1
- 1.10.2
- 1.15
- 1.17
- 1.18
- 1.22
- 1.23
- 1.25
- 1.26
- 1.27
- 1.28
- 2.0
- 2.1
- 2.2
- 2.3
- 2.4
- 2.5
- 2.6
- 2.7
- 2.8
- 2.9
- 3.0
- 3.0.1
- 3.1
- 3.2
- 3.3
- 3.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://libhx.git.sourceforge.net/git/gitweb.cgi?p=libhx/libhx%3Ba=commit%3Bh=904a46f90dd3f046bfac0b64a5e813d7cd4fca59 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html vendor-advisoryx_refsource_SUSE
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:165 vendor-advisoryx_refsource_MANDRIVA
- http://www.openwall.com/lists/oss-security/2010/08/20/12 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2010/08/20/5 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/42592 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2010/2232 vdb-entryx_refsource_VUPEN
- https://bugzilla.redhat.com/show_bug.cgi?id=625866 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| http://libhx.git.sourceforge.net/git/gitweb.cgi?p=libhx/libhx%3Ba=commit%3Bh=904a46f90dd3f046bfac0b64a5e813d7cd4fca59 | x_refsource_CONFIRM | |
| http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html | vendor-advisoryx_refsource_SUSE | |
| http://www.mandriva.com/security/advisories?name=MDVSA-2010:165 | vendor-advisoryx_refsource_MANDRIVA | |
| http://www.openwall.com/lists/oss-security/2010/08/20/12 | mailing-listx_refsource_MLIST | |
| http://www.openwall.com/lists/oss-security/2010/08/20/5 | mailing-listx_refsource_MLIST | |
| http://www.securityfocus.com/bid/42592 | vdb-entryx_refsource_BID | |
| http://www.vupen.com/english/advisories/2010/2232 | vdb-entryx_refsource_VUPEN | |
| https://bugzilla.redhat.com/show_bug.cgi?id=625866 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 24, 2010
Updated Aug 7, 2024
Reserved Aug 4, 2010
Link CVE-2010-2947
CISA Vulnrichment
Updated n/a