A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the process or potentially execute arbitrary code via a network packet.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libtoxcore | Jul 30, 2024 | Dec 13, 2021 |
| Gentoo Linux | — | Upgrade net-libs/tox. | Mar 4, 2024 | Dec 13, 2021 |
| Suse | — | Upgrade c-toxcoreUpgrade libtoxcore2Upgrade c-toxcore-develUpgrade c-toxcore-daemon | Dec 31, 2021 | Dec 13, 2021 |
| Ubuntu | — | Upgrade libtoxcore | Nov 19, 2024 | Dec 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub