CVE-2021-44847: Buffer Overflow
A stack-based buffer overflow in handlerequest function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the process or potentially execute arbitrary code via a network packet.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-44847?
CVE-2021-44847 has a medium severity rating due to its potential for remote code execution and system crashes.
How do I fix CVE-2021-44847?
To fix CVE-2021-44847, you should upgrade to a patched version of Toxcore, specifically to versions 0.1.12 or 0.2.13 and later.
Which versions are affected by CVE-2021-44847?
CVE-2021-44847 affects Toxcore versions 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12.
Can CVE-2021-44847 lead to data breaches?
Yes, CVE-2021-44847 can potentially allow remote attackers to execute arbitrary code, leading to data breaches.
What is the impact of CVE-2021-44847 on Fedora systems?
On Fedora systems, the impact of CVE-2021-44847 includes the risk of process crashes or unauthorized code execution when running affected versions.