Vulnerabilities > CVE-2017-2580 - Out-of-bounds Write vulnerability in Netpbm Project Netpbm 10.61.00

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
netpbm-project
CWE-787
nessus

Summary

An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the application to crash or possibly allow code execution.

Vulnerable Configurations

Part Description Count
Application
Netpbm_Project
1

Common Weakness Enumeration (CWE)

Nessus

  • NASL familySuSE Local Security Checks
    NASL idSUSE_SU-2019-1645-1.NASL
    descriptionThis update for netpbm fixes the following issues : Security issues fixed : CVE-2018-8975: The pm_mallocarray2 function allowed remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file (bsc#1086777). CVE-2017-2579: Fixed out-of-bounds read in expandCodeOntoStack() (bsc#1024288). CVE-2017-2580: Fixed out-of-bounds write of heap data in addPixelToRaster() function (bsc#1024291). create netpbm-vulnerable subpackage and move pstopnm there (bsc#1136936) Note that Tenable Network Security has extracted the preceding description block directly from the SUSE security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id126168
    published2019-06-24
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/126168
    titleSUSE SLED12 / SLES12 Security Update : netpbm (SUSE-SU-2019:1645-1)
  • NASL familySuSE Local Security Checks
    NASL idOPENSUSE-2019-1605.NASL
    descriptionThis update for netpbm fixes the following issues : Security issues fixed : - CVE-2017-2579: Fixed out-of-bounds read in expandCodeOntoStack() (bsc#1024288). - CVE-2017-2580: Fixed out-of-bounds write of heap data in addPixelToRaster() function (bsc#1024291). - create netpbm-vulnerable subpackage and move pstopnm there, as ghostscript is used to convert (bsc#1136936) This update was imported from the SUSE:SLE-15:Update update project.
    last seen2020-06-01
    modified2020-06-02
    plugin id126230
    published2019-06-25
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/126230
    titleopenSUSE Security Update : netpbm (openSUSE-2019-1605)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_SU-2019-1525-1.NASL
    descriptionThis update for netpbm fixes the following issues : Security issues fixed : CVE-2017-2579: Fixed out-of-bounds read in expandCodeOntoStack() (bsc#1024288). CVE-2017-2580: Fixed out-of-bounds write of heap data in addPixelToRaster() function (bsc#1024291). create netpbm-vulnerable subpackage and move pstopnm there, as ghostscript is used to convert (bsc#1136936) Note that Tenable Network Security has extracted the preceding description block directly from the SUSE security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id125989
    published2019-06-18
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/125989
    titleSUSE SLED15 / SLES15 Security Update : netpbm (SUSE-SU-2019:1525-1)