PT-2009-6692 · Silc+1 · Libsilc-1.1-2+4
Published
1970-01-01
·
Updated
2017-08-17
·
CVE-2008-7159
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SILC Toolkit versions prior to 1.1.8
libsilc-1.1-2 (affected versions not specified)
libsilc-1.1-2-dev (affected versions not specified)
libsilc-1.1-2-dbg (affected versions not specified)
Description
The issue concerns multiple vulnerabilities in the SILC Toolkit and related packages in the Debian GNU/Linux operating system. These vulnerabilities can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Specifically, the
silc asn1 encoder function in lib/silcasn1/silcasn1 encode.c is vulnerable to remote attacks that could overwrite a stack location and possibly execute arbitrary code via a crafted OID value, related to the incorrect use of a %lu format string.Recommendations
For SILC Toolkit versions prior to 1.1.8: Update to version 1.1.8 or later.
For libsilc-1.1-2, libsilc-1.1-2-dev, and libsilc-1.1-2-dbg: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Silc Toolkit
Libsilc-1.1-2
Libsilc-1.1-2-Dbg
Libsilc-1.1-2-Dev