LWN.net Logo

gmime22: arbitrary code execution

Package(s):gmime22 CVE #(s):CVE-2010-0409
Created:February 5, 2010 Updated:August 2, 2010
Description: From the Red Hat bugzilla:

Buffer overflow flaw was reported and fixed in the GMime library, in the code part responsible for calculating the maximum number of output bytes generated by an uuencode operation.

If a local user was tricked into running a specially-crafted application, using the library, it could lead to denial of service (supplied application crash) or, potentially, to arbitrary code execution with the privileges of the user running that application.

Alerts:
Debian DSA-2082-1 2010-08-02
SuSE SUSE-SR:2010:006 2010-03-15
Fedora FEDORA-2010-1484 2010-02-05
Fedora FEDORA-2010-1429 2010-02-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds