Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2015-03431

Опубликовано: 01 янв. 2015
Источник: fstec
CVSS2: 6.8
EPSS Низкий

Описание

Множественные уязвимости пакета wx2.6-headers операционной системы Debian GNU/Linux, эксплуатация которых может привести к нарушению конфиденциальности, целостности и доступности защищаемой информации. Эксплуатация уязвимостей может быть осуществлена удаленно

Вендор

Сообщество свободного программного обеспечения

Наименование ПО

Debian GNU/Linux

Версия ПО

до 4 (Debian GNU/Linux)

Тип ПО

Операционная система

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 6,8)

Возможные меры по устранению уязвимости

Проблема может быть решена обновлением операционной системы до следующих версий пакетов в зависимости от архитектуры:
Debian GNU/Linux 4:
ppc:
libwxbase2.4-1 - 2.4.5.1.1+etch1
libwxgtk2.4-1-contrib - 2.4.5.1.1+etch1
libwxgtk2.6-dev - 2.6.3.2.1.5+etch1
wx2.6-headers - 2.6.3.2.1.5+etch1
libwxbase2.6-0 - 2.6.3.2.1.5+etch1
libwxgtk2.4-dev - 2.4.5.1.1+etch1
libwxbase2.6-dev - 2.6.3.2.1.5+etch1
python-wxgtk2.4 - 2.4.5.1.1+etch1
python-wxgtk2.6 - 2.6.3.2.1.5+etch1
wx-common - 2.6.3.2.1.5+etch1
libwxgtk2.4-1 - 2.4.5.1.1+etch1
libwxgtk2.4-contrib-dev - 2.4.5.1.1+etch1
libwxgtk2.6-0 - 2.6.3.2.1.5+etch1
libwxbase2.4-dbg - 2.4.5.1.1+etch1
libwxbase2.6-dbg - 2.6.3.2.1.5+etch1
libwxgtk2.4-dbg - 2.4.5.1.1+etch1
libwxgtk2.6-dbg - 2.6.3.2.1.5+etch1
wx2.4-headers - 2.4.5.1.1+etch1
libwxbase2.4-dev - 2.4.5.1.1+etch1
i686:
libwxgtk2.4-dev - 2.4.5.1.1+etch1
libwxgtk2.4-1-contrib - 2.4.5.1.1+etch1
libwxgtk2.4-dbg - 2.4.5.1.1+etch1
wx2.6-headers - 2.6.3.2.1.5+etch1
libwxbase2.6-dbg - 2.6.3.2.1.5+etch1
wx2.4-headers - 2.4.5.1.1+etch1
libwxgtk2.6-dev - 2.6.3.2.1.5+etch1
libwxbase2.4-dev - 2.4.5.1.1+etch1
libwxbase2.6-0 - 2.6.3.2.1.5+etch1
libwxgtk2.6-0 - 2.6.3.2.1.5+etch1
libwxbase2.4-dbg - 2.4.5.1.1+etch1
python-wxgtk2.6 - 2.6.3.2.1.5+etch1
libwxgtk2.4-contrib-dev - 2.4.5.1.1+etch1
python-wxgtk2.4 - 2.4.5.1.1+etch1
libwxbase2.4-1 - 2.4.5.1.1+etch1
libwxbase2.6-dev - 2.6.3.2.1.5+etch1
wx-common - 2.6.3.2.1.5+etch1
libwxgtk2.4-1 - 2.4.5.1.1+etch1
libwxgtk2.6-dbg - 2.6.3.2.1.5+etch1
hppa:
libwxbase2.4-1 - 2.4.5.1.1+etch1
libwxgtk2.4-contrib-dev - 2.4.5.1.1+etch1
libwxgtk2.4-1 - 2.4.5.1.1+etch1
libwxbase2.4-dbg - 2.4.5.1.1+etch1
python-wxgtk2.4 - 2.4.5.1.1+etch1
libwxgtk2.4-dev - 2.4.5.1.1+etch1
libwxgtk2.4-1-contrib - 2.4.5.1.1+etch1
wx2.4-headers - 2.4.5.1.1+etch1
libwxgtk2.4-dbg - 2.4.5.1.1+etch1
libwxbase2.4-dev - 2.4.5.1.1+etch1
x86-64:
libwxgtk2.6-dev - 2.6.3.2.1.5+etch1
libwxbase2.4-dbg - 2.4.5.1.1+etch1
libwxbase2.6-dbg - 2.6.3.2.1.5+etch1
libwxbase2.4-1 - 2.4.5.1.1+etch1
libwxbase2.4-dev - 2.4.5.1.1+etch1
libwxgtk2.6-dbg - 2.6.3.2.1.5+etch1
wx2.6-headers - 2.6.3.2.1.5+etch1
libwxbase2.6-0 - 2.6.3.2.1.5+etch1
libwxgtk2.6-0 - 2.6.3.2.1.5+etch1
python-wxgtk2.4 - 2.4.5.1.1+etch1
libwxbase2.6-dev - 2.6.3.2.1.5+etch1
python-wxgtk2.6 - 2.6.3.2.1.5+etch1
libwxgtk2.4-1-contrib - 2.4.5.1.1+etch1
libwxgtk2.4-contrib-dev - 2.4.5.1.1+etch1
wx-common - 2.6.3.2.1.5+etch1
libwxgtk2.4-dbg - 2.4.5.1.1+etch1
wx2.4-headers - 2.4.5.1.1+etch1
libwxgtk2.4-dev - 2.4.5.1.1+etch1
libwxgtk2.4-1 - 2.4.5.1.1+etch1
alpha:
python-wxgtk2.4 - 2.4.5.1.1+etch1
libwxbase2.4-dev - 2.4.5.1.1+etch1
wx2.4-headers - 2.4.5.1.1+etch1
libwxgtk2.6-dbg - 2.6.3.2.1.5+etch1
wx-common - 2.6.3.2.1.5+etch1
libwxgtk2.6-dev - 2.6.3.2.1.5+etch1
libwxgtk2.4-dev - 2.4.5.1.1+etch1
libwxbase2.4-dbg - 2.4.5.1.1+etch1
libwxgtk2.4-dbg - 2.4.5.1.1+etch1
libwxgtk2.4-1 - 2.4.5.1.1+etch1
python-wxgtk2.6 - 2.6.3.2.1.5+etch1
libwxgtk2.6-0 - 2.6.3.2.1.5+etch1
libwxbase2.4-1 - 2.4.5.1.1+etch1
libwxgtk2.4-contrib-dev - 2.4.5.1.1+etch1
libwxbase2.6-0 - 2.6.3.2.1.5+etch1
libwxgtk2.4-1-contrib - 2.4.5.1.1+etch1
libwxbase2.6-dev - 2.6.3.2.1.5+etch1
wx2.6-headers - 2.6.3.2.1.5+etch1
libwxbase2.6-dbg - 2.6.3.2.1.5+etch1
ia64:
libwxbase2.4-dbg - 2.4.5.1.1+etch1
libwxgtk2.4-1-contrib - 2.4.5.1.1+etch1
libwxbase2.4-1 - 2.4.5.1.1+etch1
wx2.6-headers - 2.6.3.2.1.5+etch1
python-wxgtk2.4 - 2.4.5.1.1+etch1
libwxgtk2.4-dbg - 2.4.5.1.1+etch1
wx-common - 2.6.3.2.1.5+etch1
python-wxgtk2.6 - 2.6.3.2.1.5+etch1
libwxgtk2.6-dbg - 2.6.3.2.1.5+etch1
libwxbase2.6-0 - 2.6.3.2.1.5+etch1
libwxgtk2.4-1 - 2.4.5.1.1+etch1
libwxgtk2.6-0 - 2.6.3.2.1.5+etch1
libwxbase2.4-dev - 2.4.5.1.1+etch1
libwxgtk2.6-dev - 2.6.3.2.1.5+etch1
libwxbase2.6-dbg - 2.6.3.2.1.5+etch1
libwxbase2.6-dev - 2.6.3.2.1.5+etch1
wx2.4-headers - 2.4.5.1.1+etch1
libwxgtk2.4-dev - 2.4.5.1.1+etch1
libwxgtk2.4-contrib-dev - 2.4.5.1.1+etch1
mips:
libwxbase2.4-dbg - 2.4.5.1.1+etch1
libwxgtk2.6-dbg - 2.6.3.2.1.5+etch1
libwxgtk2.4-1-contrib - 2.4.5.1.1+etch1
libwxbase2.4-1 - 2.4.5.1.1+etch1
python-wxgtk2.6 - 2.6.3.2.1.5+etch1
wx2.6-headers - 2.6.3.2.1.5+etch1
python-wxgtk2.4 - 2.4.5.1.1+etch1
wx-common - 2.6.3.2.1.5+etch1
libwxgtk2.4-1 - 2.4.5.1.1+etch1
libwxbase2.6-dbg - 2.6.3.2.1.5+etch1
libwxgtk2.6-dev - 2.6.3.2.1.5+etch1
libwxbase2.4-dev - 2.4.5.1.1+etch1
libwxgtk2.4-dbg - 2.4.5.1.1+etch1
wx2.4-headers - 2.4.5.1.1+etch1
libwxgtk2.6-0 - 2.6.3.2.1.5+etch1
libwxgtk2.4-contrib-dev - 2.4.5.1.1+etch1
libwxbase2.6-0 - 2.6.3.2.1.5+etch1
libwxbase2.6-dev - 2.6.3.2.1.5+etch1
libwxgtk2.4-dev - 2.4.5.1.1+etch1
noarch:
wx2.6-i18n - 2.6.3.2.1.5+etch1
python-wxtools - 2.6.3.2.1.5+etch1
wx2.6-examples - 2.6.3.2.1.5+etch1
wx2.6-doc - 2.6.3.2.1.5+etch1
wx2.4-i18n - 2.4.5.1.1+etch1
python-wxversion - 2.6.3.2.1.5+etch1
wx2.4-doc - 2.4.5.1.1+etch1
wx2.4-examples - 2.4.5.1.1+etch1
mipsel:
python-wxgtk2.6 - 2.6.3.2.1.5+etch1
libwxgtk2.4-dbg - 2.4.5.1.1+etch1
libwxgtk2.4-1 - 2.4.5.1.1+etch1
libwxgtk2.6-dbg - 2.6.3.2.1.5+etch1
python-wxgtk2.4 - 2.4.5.1.1+etch1
wx2.6-headers - 2.6.3.2.1.5+etch1
libwxgtk2.4-1-contrib - 2.4.5.1.1+etch1
libwxgtk2.6-0 - 2.6.3.2.1.5+etch1
libwxbase2.4-dbg - 2.4.5.1.1+etch1
libwxbase2.6-0 - 2.6.3.2.1.5+etch1
libwxgtk2.4-contrib-dev - 2.4.5.1.1+etch1
wx-common - 2.6.3.2.1.5+etch1
libwxbase2.4-1 - 2.4.5.1.1+etch1
libwxbase2.4-dev - 2.4.5.1.1+etch1
libwxgtk2.4-dev - 2.4.5.1.1+etch1
libwxbase2.6-dbg - 2.6.3.2.1.5+etch1
libwxgtk2.6-dev - 2.6.3.2.1.5+etch1
wx2.4-headers - 2.4.5.1.1+etch1
libwxbase2.6-dev - 2.6.3.2.1.5+etch1
arm:
python-wxgtk2.6 - 2.6.3.2.1.5+etch1
wx2.6-headers - 2.6.3.2.1.5+etch1
libwxgtk2.6-dbg - 2.6.3.2.1.5+etch1
libwxbase2.6-dbg - 2.6.3.2.1.5+etch1
wx-common - 2.6.3.2.1.5+etch1
libwxbase2.6-0 - 2.6.3.2.1.5+etch1
libwxgtk2.6-0 - 2.6.3.2.1.5+etch1
libwxbase2.6-dev - 2.6.3.2.1.5+etch1
libwxgtk2.6-dev - 2.6.3.2.1.5+etch1
Debian GNU/Linux 5:
ppc:
python-wxgtk2.6-dbg - 2.6.3.2.2-3+lenny1
wx2.8-headers - 2.8.7.1-1.1+lenny1
wx-common - 2.6.3.2.2-3+lenny1
libwxgtk2.6-dbg - 2.6.3.2.2-3+lenny1
libwxgtk2.6-dev - 2.6.3.2.2-3+lenny1
libwxgtk2.8-0 - 2.8.7.1-1.1+lenny1
libwxgtk2.8-dbg - 2.8.7.1-1.1+lenny1
python-wxgtk2.8-dbg - 2.8.7.1-1.1+lenny1
wx2.6-headers - 2.6.3.2.2-3+lenny1
python-wxgtk2.8 - 2.8.7.1-1.1+lenny1
libwxbase2.6-0 - 2.6.3.2.2-3+lenny1
libwxbase2.8-0 - 2.8.7.1-1.1+lenny1
libwxbase2.6-dev - 2.6.3.2.2-3+lenny1
libwxbase2.8-dev - 2.8.7.1-1.1+lenny1
libwxgtk2.8-dev - 2.8.7.1-1.1+lenny1
libwxbase2.6-dbg - 2.6.3.2.2-3+lenny1
python-wxgtk2.6 - 2.6.3.2.2-3+lenny1
libwxbase2.8-dbg - 2.8.7.1-1.1+lenny1
libwxgtk2.6-0 - 2.6.3.2.2-3+lenny1
i686:
libwxbase2.8-dbg - 2.8.7.1-1.1+lenny1
libwxgtk2.8-dev - 2.8.7.1-1.1+lenny1
python-wxgtk2.6 - 2.6.3.2.2-3+lenny1
libwxbase2.8-0 - 2.8.7.1-1.1+lenny1
python-wxgtk2.6-dbg - 2.6.3.2.2-3+lenny1
wx2.8-headers - 2.8.7.1-1.1+lenny1
libwxgtk2.6-0 - 2.6.3.2.2-3+lenny1
libwxgtk2.6-dbg - 2.6.3.2.2-3+lenny1
python-wxgtk2.8 - 2.8.7.1-1.1+lenny1
libwxbase2.8-dev - 2.8.7.1-1.1+lenny1
libwxgtk2.8-dbg - 2.8.7.1-1.1+lenny1
wx2.6-headers - 2.6.3.2.2-3+lenny1
libwxgtk2.8-0 - 2.8.7.1-1.1+lenny1
python-wxgtk2.8-dbg - 2.8.7.1-1.1+lenny1
libwxbase2.6-0 - 2.6.3.2.2-3+lenny1
libwxgtk2.6-dev - 2.6.3.2.2-3+lenny1
wx-common - 2.6.3.2.2-3+lenny1
libwxbase2.6-dev - 2.6.3.2.2-3+lenny1
libwxbase2.6-dbg - 2.6.3.2.2-3+lenny1
x86-64:
python-wxgtk2.8-dbg - 2.8.7.1-1.1+lenny1
wx2.8-headers - 2.8.7.1-1.1+lenny1
libwxbase2.8-dbg - 2.8.7.1-1.1+lenny1
libwxbase2.6-dev - 2.6.3.2.2-3+lenny1
libwxgtk2.8-dev - 2.8.7.1-1.1+lenny1
libwxbase2.6-0 - 2.6.3.2.2-3+lenny1
python-wxgtk2.6 - 2.6.3.2.2-3+lenny1
libwxgtk2.6-dbg - 2.6.3.2.2-3+lenny1
libwxgtk2.8-dbg - 2.8.7.1-1.1+lenny1
libwxgtk2.6-dev - 2.6.3.2.2-3+lenny1
wx-common - 2.6.3.2.2-3+lenny1
python-wxgtk2.8 - 2.8.7.1-1.1+lenny1
libwxbase2.8-dev - 2.8.7.1-1.1+lenny1
wx2.6-headers - 2.6.3.2.2-3+lenny1
libwxbase2.6-dbg - 2.6.3.2.2-3+lenny1
libwxbase2.8-0 - 2.8.7.1-1.1+lenny1
libwxgtk2.6-0 - 2.6.3.2.2-3+lenny1
libwxgtk2.8-0 - 2.8.7.1-1.1+lenny1
python-wxgtk2.6-dbg - 2.6.3.2.2-3+lenny1
armel:
python-wxgtk2.8-dbg - 2.8.7.1-1.1+lenny1
libwxbase2.8-dbg - 2.8.7.1-1.1+lenny1
libwxbase2.8-0 - 2.8.7.1-1.1+lenny1
wx2.8-headers - 2.8.7.1-1.1+lenny1
libwxgtk2.8-0 - 2.8.7.1-1.1+lenny1
libwxgtk2.8-dbg - 2.8.7.1-1.1+lenny1
python-wxgtk2.8 - 2.8.7.1-1.1+lenny1
libwxbase2.8-dev - 2.8.7.1-1.1+lenny1
libwxgtk2.8-dev - 2.8.7.1-1.1+lenny1
alpha:
python-wxgtk2.8-dbg - 2.8.7.1-1.1+lenny1
wx-common - 2.6.3.2.2-3+lenny1
wx2.6-headers - 2.6.3.2.2-3+lenny1
libwxgtk2.8-0 - 2.8.7.1-1.1+lenny1
python-wxgtk2.8 - 2.8.7.1-1.1+lenny1
libwxbase2.8-dev - 2.8.7.1-1.1+lenny1
libwxgtk2.6-dev - 2.6.3.2.2-3+lenny1
wx2.8-headers - 2.8.7.1-1.1+lenny1
libwxgtk2.6-dbg - 2.6.3.2.2-3+lenn

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 81%
0.01557
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 16 лет назад

Integer overflow in the wxImage::Create function in src/common/image.cpp in wxWidgets 2.8.10 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted JPEG file, which triggers a heap-based buffer overflow. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

redhat
около 16 лет назад

Integer overflow in the wxImage::Create function in src/common/image.cpp in wxWidgets 2.8.10 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted JPEG file, which triggers a heap-based buffer overflow. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

nvd
около 16 лет назад

Integer overflow in the wxImage::Create function in src/common/image.cpp in wxWidgets 2.8.10 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted JPEG file, which triggers a heap-based buffer overflow. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

debian
около 16 лет назад

Integer overflow in the wxImage::Create function in src/common/image.c ...

github
больше 3 лет назад

Integer overflow in the wxImage::Create function in src/common/image.cpp in wxWidgets 2.8.10 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted JPEG file, which triggers a heap-based buffer overflow. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS

Процентиль: 81%
0.01557
Низкий

6.8 Medium

CVSS2