Vulnerabilities > CVE-2017-2579 - Out-of-bounds Read vulnerability in Netpbm Project Netpbm 10.61.00

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
netpbm-project
CWE-125
nessus

Summary

An out-of-bounds read vulnerability was found in netpbm before 10.61. The expandCodeOntoStack() function has an insufficient code value check, so that a maliciously crafted file could cause the application to crash or possibly allows code execution.

Vulnerable Configurations

Part Description Count
Application
Netpbm_Project
1

Common Weakness Enumeration (CWE)

Common Attack Pattern Enumeration and Classification (CAPEC)

  • Overread Buffers
    An adversary attacks a target by providing input that causes an application to read beyond the boundary of a defined buffer. This typically occurs when a value influencing where to start or stop reading is set to reflect positions outside of the valid memory location of the buffer. This type of attack may result in exposure of sensitive information, a system crash, or arbitrary code execution.

Nessus

  • NASL familySuSE Local Security Checks
    NASL idSUSE_SU-2019-1645-1.NASL
    descriptionThis update for netpbm fixes the following issues : Security issues fixed : CVE-2018-8975: The pm_mallocarray2 function allowed remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file (bsc#1086777). CVE-2017-2579: Fixed out-of-bounds read in expandCodeOntoStack() (bsc#1024288). CVE-2017-2580: Fixed out-of-bounds write of heap data in addPixelToRaster() function (bsc#1024291). create netpbm-vulnerable subpackage and move pstopnm there (bsc#1136936) Note that Tenable Network Security has extracted the preceding description block directly from the SUSE security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id126168
    published2019-06-24
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/126168
    titleSUSE SLED12 / SLES12 Security Update : netpbm (SUSE-SU-2019:1645-1)
  • NASL familySuSE Local Security Checks
    NASL idOPENSUSE-2019-1605.NASL
    descriptionThis update for netpbm fixes the following issues : Security issues fixed : - CVE-2017-2579: Fixed out-of-bounds read in expandCodeOntoStack() (bsc#1024288). - CVE-2017-2580: Fixed out-of-bounds write of heap data in addPixelToRaster() function (bsc#1024291). - create netpbm-vulnerable subpackage and move pstopnm there, as ghostscript is used to convert (bsc#1136936) This update was imported from the SUSE:SLE-15:Update update project.
    last seen2020-06-01
    modified2020-06-02
    plugin id126230
    published2019-06-25
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/126230
    titleopenSUSE Security Update : netpbm (openSUSE-2019-1605)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_SU-2019-1525-1.NASL
    descriptionThis update for netpbm fixes the following issues : Security issues fixed : CVE-2017-2579: Fixed out-of-bounds read in expandCodeOntoStack() (bsc#1024288). CVE-2017-2580: Fixed out-of-bounds write of heap data in addPixelToRaster() function (bsc#1024291). create netpbm-vulnerable subpackage and move pstopnm there, as ghostscript is used to convert (bsc#1136936) Note that Tenable Network Security has extracted the preceding description block directly from the SUSE security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id125989
    published2019-06-18
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/125989
    titleSUSE SLED15 / SLES15 Security Update : netpbm (SUSE-SU-2019:1525-1)