|
|
| |
|
| |
mcrypt: code execution
| Package(s): | mcrypt |
CVE #(s): | CVE-2012-4409
|
| Created: | September 19, 2012 |
Updated: | October 17, 2012 |
| Description: |
From the Red Hat bugzilla:
A buffer overflow was reported in mcrypt version 2.6.8 and earlier due to a boundary error in the processing of an encrypted file (via the check_file_head() function in src/extra.c). If a user were tricked into attempting to decrypt a specially-crafted .nc encrypted flie, this flaw would cause a stack-based buffer overflow that could potentially lead to arbitrary code execution. |
| Alerts: |
|
( Log in to post comments)
|
|
|