PT-2009-6692 · Silc+1 · Libsilc-1.1-2+4

Published

1970-01-01

·

Updated

2017-08-17

·

CVE-2008-7159

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SILC Toolkit versions prior to 1.1.8 libsilc-1.1-2 (affected versions not specified) libsilc-1.1-2-dev (affected versions not specified) libsilc-1.1-2-dbg (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the SILC Toolkit and related packages in the Debian GNU/Linux operating system. These vulnerabilities can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Specifically, the silc asn1 encoder function in lib/silcasn1/silcasn1 encode.c is vulnerable to remote attacks that could overwrite a stack location and possibly execute arbitrary code via a crafted OID value, related to the incorrect use of a %lu format string.
Recommendations For SILC Toolkit versions prior to 1.1.8: Update to version 1.1.8 or later. For libsilc-1.1-2, libsilc-1.1-2-dev, and libsilc-1.1-2-dbg: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of Externally-Controlled Format String

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02900
BDU:2015-02901
BDU:2015-02902
BDU:2015-02903
CVE-2008-7159
DSA-1879-1

Affected Products

Debian
Silc Toolkit
Libsilc-1.1-2
Libsilc-1.1-2-Dbg
Libsilc-1.1-2-Dev