Lucene search

K
gentooGentoo FoundationGLSA-200903-13
HistoryMar 09, 2009 - 12:00 a.m.

MPFR: Denial of service

2009-03-0900:00:00
Gentoo Foundation
security.gentoo.org
10

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.008

Percentile

82.2%

Background

MPFR is a library for multiple-precision floating-point computations with exact rounding.

Description

Multiple buffer overflows have been reported in the mpfr_snprintf() and mpfr_vsnprintf() functions.

Impact

A remote user could exploit the vulnerability to cause a Denial of Service in an application using MPFR via unknown vectors.

Workaround

There is no known workaround at this time.

Resolution

All MPRF users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=dev-libs/mpfr-2.4.1"
OSVersionArchitecturePackageVersionFilename
Gentooanyalldev-libs/mpfr< 2.4.1UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.008

Percentile

82.2%