abcm2ps: Multiple vulnerabilities Multiple vulnerabilities, including buffer overflows, have been found in abcm2ps. abcm2ps 2011-11-20 2011-11-20 322859 remote 5.9.13 5.9.13

abcm2ps is a program to convert abc files to Postscript files.

Multiple vulnerabilities have been discovered in abcm2ps:

A remote attacker could entice a user to load a specially crafted ABC file or use a long -O option on the command line, resulting in the execution of arbitrary code.

There is no known workaround at this time.

All abcm2ps users should upgrade to the latest stable version:

# emerge --sync # emerge --ask --oneshot --verbose ">=media-sound/abcm2ps-5.9.13"

NOTE: This is a legacy GLSA. Updates for all affected architectures are available since August 27, 2010. It is likely that your system is already no longer affected by this issue.

CVE-2010-3441 CVE-2010-4743 CVE-2010-4744 underling ackle