First published: Wed Nov 21 2012(Updated: )
Multiple format string vulnerabilities in mcrypt 2.6.8 and earlier might allow user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving (1) errors.c or (2) mcrypt.c.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Libgcrypt | <=2.6.8 | |
Libgcrypt | =2.6.4 | |
Libgcrypt | =2.6.5 | |
Libgcrypt | =2.6.6 | |
Libgcrypt | =2.6.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4426 has a medium severity rating due to the potential for denial of service and arbitrary code execution.
To fix CVE-2012-4426, upgrade to mcrypt version 2.6.9 or later.
CVE-2012-4426 affects mcrypt versions 2.6.8 and earlier.
CVE-2012-4426 can enable user-assisted remote attackers to potentially cause a denial of service or execute arbitrary code.
CVE-2012-4426 involves format string vulnerabilities in mcrypt's errors.c and mcrypt.c.