REDHAT-BUG-1409754: Buffer Overflow
Published Jan 3, 2017
·Updated
A heap-buffer overflow vulnerability was discovered in cryptopp. This vulnerability can be used to remotely gain access to shell.
References:
http://seclists.org/oss-sec/2016/q4/760 https://pony7.fr/ctf:public:32c3:cryptmsg
Upstream bug:
https://github.com/dlitz/pycrypto/issues/176
Affected Software
1 affected component
Cryptopp cryptopp
Event History
Jan 3, 2017
Data Sourced
via Red Hat·09:13 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1409754?
The severity of REDHAT-BUG-1409754 is critical due to the potential for remote code execution.
2
How do I fix REDHAT-BUG-1409754?
To fix REDHAT-BUG-1409754, you should update to the latest patched version of cryptopp.
3
What versions of cryptopp are affected by REDHAT-BUG-1409754?
All versions of cryptopp prior to the security fix are potentially affected by REDHAT-BUG-1409754.
4
Can REDHAT-BUG-1409754 be exploited remotely?
Yes, REDHAT-BUG-1409754 can be exploited remotely to gain unauthorized access.
5
What is the nature of the vulnerability in REDHAT-BUG-1409754?
The vulnerability in REDHAT-BUG-1409754 is a heap-buffer overflow that can lead to arbitrary code execution.