CVE-2018-10753

NameCVE-2018-10753
DescriptionStack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severityhigh (attack range: remote)
Debian Bugs897966

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
abcm2ps (PTS)buster, sid, jessie, stretch7.8.9-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
abcm2pssource(unstable)(unfixed)unimportant897966

Notes

https://github.com/leesavide/abcm2ps/issues/16
https://github.com/leesavide/abcm2ps/commit/fd956e19f88ee32f8ec4aece5901400b06e80bcc
Crash in CLI tool, no security impact

Search for package or bug name: Reporting problems