Common Data Format Library Multiple Memory Corruption Vulnerabilities
BID:35754
Info
Common Data Format Library Multiple Memory Corruption Vulnerabilities
| Bugtraq ID: | 35754 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 21 2009 12:00AM |
| Updated: | Aug 21 2009 03:57PM |
| Credit: | Leon Juranic |
| Vulnerable: |
NASA Goddard Space Flight Center CDF 3.2.4 Gentoo Linux |
| Not Vulnerable: |
NASA Goddard Space Flight Center CDF 3.3 |
Discussion
Common Data Format Library Multiple Memory Corruption Vulnerabilities
The Common Data Format (CDF) library is prone to multiple memory-corruption vulnerabilities.
An attacker can exploit these issues by tricking a victim into opening a specially crafted CDF file.
A successful attack will allow attacker-supplied code to run in the context of the victim opening the file. Failed exploit attempts will result in a denial-of-service condition.
CDF 3.2.4 is vulnerable; other versions may also be affected.
The Common Data Format (CDF) library is prone to multiple memory-corruption vulnerabilities.
An attacker can exploit these issues by tricking a victim into opening a specially crafted CDF file.
A successful attack will allow attacker-supplied code to run in the context of the victim opening the file. Failed exploit attempts will result in a denial-of-service condition.
CDF 3.2.4 is vulnerable; other versions may also be affected.
Exploit / POC
Common Data Format Library Multiple Memory Corruption Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Common Data Format Library Multiple Memory Corruption Vulnerabilities
Solution:
The vendor has released fixes. Please see the references for details.
Solution:
The vendor has released fixes. Please see the references for details.
References
Common Data Format Library Multiple Memory Corruption Vulnerabilities
References:
References:
- Common Data Format (CDF) Version 3.3.0 Release Notes (NASA Goddard Space Flight Center)
- INFIGO IS Security Advisory #INFIGO-2009-07-09 (INFIGO)
- Vendor Homepage (NASA Goddard Space Flight Center)