[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-2080Date: (C)2008-05-06   (M)2023-12-22


Stack-based buffer overflow in the Read32s_64 function in src/lib/cdfread64.c in the NASA Goddard Space Flight Center Common Data Format (CDF) library before 3.2.1 allows context-dependent attackers to execute arbitrary code via a .cdf file with crafted length tags.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1019965
BID-29045
SECUNIA-30053
SECUNIA-30169
ADV-2008-1440
GLSA-200805-14
cdf-read32s64-bo(42219)
http://cdf.gsfc.nasa.gov/CDF32_buffer_overflow.html
http://www.coresecurity.com/?action=item&id=2260

CWE    1
CWE-119

© SecPod Technologies