Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to execute arbitrary code via an encrypted file with a crafted header containing long salt data that is not properly handled during decryption.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade mcrypt | Jul 30, 2024 | Nov 21, 2012 |
| Gentoo Linux | — | Upgrade app-crypt/mcrypt. | Oct 30, 2017 | Nov 21, 2012 |
| Suse | — | Upgrade mcryptUpgrade mcrypt-debugsourceUpgrade mcrypt-debuginfo | Dec 12, 2013 | Nov 21, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub