CVE-2019-1010060

NameCVE-2019-1010060
DescriptionNASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is: remote unauthenticated attacker. The fixed version is: 3.43. NOTE: this CVE refers to the issues not covered by CVE-2018-3846, CVE-2018-3847, CVE-2018-3848, and CVE-2018-3849. One example is ftp_status in drvrnet.c mishandling a long string beginning with a '4' character.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs892458

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
cfitsio (PTS)jessie3.370-2+deb8u1vulnerable
stretch3.410-1vulnerable
buster3.450-3fixed
bullseye3.490-3fixed
bookworm4.2.0-3fixed
sid, trixie4.3.1-1.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cfitsiosourcewheezy(unfixed)end-of-life
cfitsiosource(unstable)3.430-1low892458

Notes

[stretch] - cfitsio <no-dsa> (Minor issue)
[jessie] - cfitsio <no-dsa> (Minor issue)
The issue is specifically to other issues not covered by CVE-2018-3846,
CVE-2018-3847, CVE-2018-3848, and CVE-2018-3849 but fixed in 3.43. One
example is ftp_status in drvrnet.c mishandling a long string beginning
with a '4' character.

Search for package or bug name: Reporting problems