FEDORA-2012-17482Vendor advisory
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091932.html CVE-2012-4552
PLIB 1.8.5 - 'ssg/ssgParser.cxx' Local Buffer Overflow
Record summary
CVE-2012-4552 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Stack-based buffer overflow in the error function in ssg/ssgParser.cxx in PLIB 1.8.5 allows remote attackers to execute arbitrary code via a crafted 3d model file that triggers a long error message, as demonstrated by a .ase file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPLIB 1.8.5 - 'ssg/ssgParser.cxx' Local Buffer OverflowExploitDB exploitby Andrés GómezNot analyzed1 file
References
10FEDORA-2012-17465Vendor advisory
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091937.html FEDORA-2012-17517Vendor advisory
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091964.html openSUSE-SU-2012:1506Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00013.html openSUSE-SU-2013:0146Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00015.html 51340Third-party advisory
http://secunia.com/advisories/51340 [oss-security] 20121029 Re: CVE Request: PLIB 1.8.5 ssg/ssgParser.cxx Buffer Overflowmailing list
http://www.openwall.com/lists/oss-security/2012/10/29/9 87001vdb entry
http://www.osvdb.org/87001 bugzilla.redhat.com
https://bugzilla.redhat.com/show_bug.cgi?id=871187 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-4552