7.2
CVSSv2

CVE-2010-1620

Published: 12/05/2010 Updated: 12/05/2010
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer overflow in the load_iface function in Tools/gdomap.c in gdomap in GNUstep Base prior to 1.20.0 might allow context-dependent malicious users to execute arbitrary code via a (1) file or (2) socket that provides configuration data with many entries, leading to a heap-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

gnustep gnustep base 1.19.2

gnustep gnustep base 1.19.0

gnustep gnustep base 1.14.0

gnustep gnustep base 1.12.0

gnustep gnustep base

gnustep gnustep base 1.17.0

gnustep gnustep base 1.15.4

gnustep gnustep base 1.15.2

gnustep gnustep base 1.15.1

gnustep gnustep base 1.19.1

gnustep gnustep base 1.18.0

gnustep gnustep base 1.15.0

gnustep gnustep base 1.13.0

gnustep gnustep base 1.11.2

Vendor Advisories

Debian Bug report logs - #584401 CVE-2010-1620: Integer overflow Package: gnustep-base; Maintainer for gnustep-base is Debian GNUstep maintainers <pkg-gnustep-maintainers@listsaliothdebianorg>; Reported by: Giuseppe Iuculano <iuculano@debianorg> Date: Thu, 3 Jun 2010 10:45:01 UTC Severity: serious Tags: security ...