CRITICAL
NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow
Published Jul 16, 2019
9.8
CRITICALCVSS 3.0
EPSS 7.17%
Description
NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is: remote unauthenticated attacker. The fixed version is: 3.43. NOTE: this CVE refers to the issues not covered by CVE-2018-3846, CVE-2018-3847, CVE-2018-3848, and CVE-2018-3849. One example is ftp_status in drvrnet.c mishandling a long string beginning with a '4' character.
Affected products
-
- Version < 3.43 [fixed: 3.43]StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=892458 x_refsource_MISCMailing ListThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-1809 Advisory
- https://github.com/astropy/astropy/pull/7274 x_refsource_MISCThird Party Advisory
- https://heasarc.gsfc.nasa.gov/FTP/software/fitsio/c/cfitsio3420.tar.gz x_refsource_MISCThird Party AdvisoryUS Government Resource
- https://heasarc.gsfc.nasa.gov/FTP/software/fitsio/c/cfitsio3430.tar.gz x_refsource_MISCThird Party AdvisoryUS Government Resource
- https://heasarc.gsfc.nasa.gov/FTP/software/fitsio/c/docs/changes2.txt x_refsource_MISCThird Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=892458 | x_refsource_MISCMailing ListThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-1809 | Advisory | |
| https://github.com/astropy/astropy/pull/7274 | x_refsource_MISCThird Party Advisory | |
| https://heasarc.gsfc.nasa.gov/FTP/software/fitsio/c/cfitsio3420.tar.gz | x_refsource_MISCThird Party AdvisoryUS Government Resource | |
| https://heasarc.gsfc.nasa.gov/FTP/software/fitsio/c/cfitsio3430.tar.gz | x_refsource_MISCThird Party AdvisoryUS Government Resource | |
| https://heasarc.gsfc.nasa.gov/FTP/software/fitsio/c/docs/changes2.txt | x_refsource_MISCThird Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner dwf
Published Jul 16, 2019
Updated Aug 5, 2024
Reserved Mar 20, 2019
Link CVE-2019-1010060
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-1809 Assigner dwf
Published Jul 16, 2019
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2019-1809