Lucene search

K
ubuntuUbuntuUSN-772-1
HistoryMay 07, 2009 - 12:00 a.m.

MPFR vulnerability

2009-05-0700:00:00
ubuntu.com
34

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.008

Percentile

82.2%

Releases

  • Ubuntu 9.04

Packages

  • mpfr -

Details

It was discovered that MPFR improperly handled string lengths in its print
routines. If a user or automated system were tricked into processing
specially crafted data with applications linked against MPFR, an attacker
could cause a denial of service or execute arbitrary code with privileges
of the user invoking the program.

OSVersionArchitecturePackageVersionFilename
Ubuntu9.04noarchlibmpfr1ldbl< 2.4.0-1ubuntu3.1UNKNOWN
Ubuntu9.04noarchlibmpfr-dev< 2.4.0-1ubuntu3.1UNKNOWN
Ubuntu9.04noarchlib64mpfr1< 2.4.0-1ubuntu3.1UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.008

Percentile

82.2%