Vulnerabilities > CVE-2006-3145 - Remote Off-By-One Buffer Overflow vulnerability in NetPBM Pamtofits

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
netpbm
nessus

Summary

Buffer overflow in pamtofits of NetPBM 10.30 through 10.33 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code when assembling the header, possibly related to an off-by-one error.

Vulnerable Configurations

Part Description Count
Application
Netpbm
4

Nessus

NASL familyMandriva Local Security Checks
NASL idMANDRAKE_MDKA-2006-026.NASL
descriptionThe pnmtopalm program, part of netpbm, crashes on many images. (#21020) The pnmtofits program, part of netpbm, crashes during conversion. (#21444) Updated packages have been patched to correct these issues.
last seen2017-10-29
modified2012-09-07
plugin id24508
published2007-02-18
reporterTenable
sourcehttps://www.tenable.com/plugins/index.php?view=single&id=24508
titleMDKA-2006:026 : netpbm

Statements

contributorMark J Cox
lastmodified2006-08-30
organizationRed Hat
statementThis issue did not affect the versions of NetPBM distributed with Red Hat Enterprise Linux 2.1, 3, or 4.