CVE-2008-7160: Medium severity silc toolkit vulnerability
The silchttpserverparse function in lib/silchttp/silchttpserver.c in the internal HTTP server in silcd in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.9 allows remote attackers to overwrite a stack location and possibly execute arbitrary code via a crafted Content-Length header, related to incorrect use of a %lu format string.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-7160?
CVE-2008-7160 has a moderate severity, as it allows remote attackers to overwrite a stack location and potentially execute arbitrary code.
How do I fix CVE-2008-7160?
To fix CVE-2008-7160, update to version 1.1.9 or later of the SILC Toolkit.
What software is affected by CVE-2008-7160?
CVE-2008-7160 affects several versions of the SILC Toolkit, specifically versions prior to 1.1.9.
Can CVE-2008-7160 be exploited remotely?
Yes, CVE-2008-7160 can be exploited remotely through a crafted Content-Length header in an HTTP request.
What are the potential impacts of CVE-2008-7160?
The potential impacts of CVE-2008-7160 include arbitrary code execution and service disruption.