SB2018032607 - Gentoo update for PLIB
Published: March 26, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Stack-based buffer overflow (CVE-ID: CVE-2012-4552)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists in the error function in ssg/ssgParser.cxx due to boundary error. A remote attacker can trigger stack-based buffer overflow and execute arbitrary code on the target system via a specially crafted 3d model file that triggers a long error message, as demonstrated by a .ase file.
Successful exploitation of the vulnerability may result in system compromise.
Remediation
Install update from vendor's website.