CVE-2007-5197: Buffer Overflow
Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code via unspecified vectors related to Reduce in Montgomery-based Pow methods.
Other sources
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5197
"Buffer overflow in the Mono.Math.BigInteger class in Mono allows context-dependent attackers to execute arbitrary code via unspecified vectors."
Patch extracted from Debian's 1.2.2.1-1etch1 patchkit (attached) seems to apply to 1.2.5.1 in devel with some line offsets, I have done no further analysis.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5197?
CVE-2007-5197 has been classified with a high severity due to its potential to allow execution of arbitrary code through a buffer overflow.
How do I fix CVE-2007-5197?
To fix CVE-2007-5197, upgrade Mono to a patched version that addresses the buffer overflow vulnerability.
Which versions of Mono are affected by CVE-2007-5197?
CVE-2007-5197 affects Mono versions up to and including 1.2.5.1.
What type of vulnerability is CVE-2007-5197?
CVE-2007-5197 is a buffer overflow vulnerability found in the Mono.Math.BigInteger class.
Can this vulnerability be exploited remotely in CVE-2007-5197?
Yes, CVE-2007-5197 can potentially be exploited by remote, context-dependent attackers.