Back

HIGH

cfitsio: Unsafe use of sprintf() can allow a remote unauthenticated attacker to execute arbitrary code

Published Apr 16, 2018

Description

In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner talos
Published Apr 16, 2018
Updated Sep 17, 2024
Reserved Jan 2, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Mar 10, 2018