CVE-2010-2891
libsmi - buffer overflow
EPSS 14.0%
Description
Buffer overflow in the smiGetNode function in lib/smi.c in libsmi 0.4.8 allows context-dependent attackers to execute arbitrary code via an Object Identifier (aka OID) represented as a numerical string containing many components separated by . (dot) characters.
How to fix CVE-2010-2891
To remediate CVE-2010-2891, upgrade the affected package to a fixed version below.
- Debian/libsmi—upgrade to 0.4.8+dfsg2-3 or later
- Debian/libsmi—upgrade to 0.4.7+dfsg-0.2 or later
Is CVE-2010-2891 being exploited?
Moderate — EPSS is 14.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 0.4.8+dfsg2-3
- from 0, < 0.4.7+dfsg-0.2