CVE-2023-36328: Integer Overflow
Published Sep 1, 2023
·Updated
Integer Overflow vulnerability in mpgrow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial of service (DoS).
Affected Software
12 affected componentsFixes available
debian/libtommath<=1.1.0-3, <=1.2.0-6
1.2.1-2
ubuntu/libtommath<1.0.1-1ubuntu0.1~
1.0.1-1ubuntu0.1~
ubuntu/libtommath<1.2.0-3ubuntu0.1
1.2.0-3ubuntu0.1
ubuntu/libtommath<1.2.0-6ubuntu0.22.04.1
1.2.0-6ubuntu0.22.04.1
ubuntu/libtommath<1.2.0-6ubuntu0.23.04.1
1.2.0-6ubuntu0.23.04.1
ubuntu/libtommath<1.2.0-6ubuntu0.23.10.1
1.2.0-6ubuntu0.23.10.1
ubuntu/libtommath<0.42.0-1.2ubuntu0.1~
0.42.0-1.2ubuntu0.1~
LibTom libtommath<1.2.1
Fedoraproject Fedora=37
Fedoraproject Fedora=38
Fedoraproject Fedora=39
LibTom libtommath<2023-05-09
Remediation
Patch Available
Event History
Sep 1, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 12, 2024
Data Sourced
via Launchpad·12:21 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-36328.
2
What is the severity of CVE-2023-36328?
The severity of CVE-2023-36328 is critical with a CVSS score of 9.8.
3
What is the affected software for CVE-2023-36328?
The affected software for CVE-2023-36328 is libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9 and Fedoraproject Fedora 38.
4
How does CVE-2023-36328 affect the system?
CVE-2023-36328 allows attackers to execute arbitrary code and cause a denial of service (DoS).
5
Are there any references for CVE-2023-36328?
Yes, the references for CVE-2023-36328 are: [1] [2] [3]