CVE-2019-1010060

UnknownEPSS 7.17%

Last modified

CVE-2019-1010060 is a vulnerability of currently unknown severity. NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. EPSS estimates a 7.17% chance of exploitation in the next 30 days.

Description

NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is: remote unauthenticated attacker. The fixed version is: 3.43. NOTE: this CVE refers to the issues not covered by CVE-2018-3846, CVE-2018-3847, CVE-2018-3848, and CVE-2018-3849. One example is ftp_status in drvrnet.c mishandling a long string beginning with a '4' character.

Metrics

EPSS Probability
7.17%

93.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
NasaCfitsio< 3.43

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-1010060?
NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is: remote unauthenticated attacker. The fixed version is: 3.43. NOTE: this CVE refers to the issues not covered by CVE-2018-3846, CVE-2018-3847, CVE-2018-3848, and CVE-2018-3849. One example is ftp_status in drvrnet.c mishandling a long string beginning with a '4' character.
How severe is CVE-2019-1010060?
Severity scoring for CVE-2019-1010060 is pending analysis. The EPSS model estimates a 7.17% probability of exploitation in the next 30 days.
How do I fix CVE-2019-1010060?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-1010060?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST