V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2021-44847
DEB
Critical

A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an im…

CVSS
9.8
Critical
EPSS
0.04
p89
Published
2021-01-01
Updated
2021-01-01
Description

A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the process or potentially execute arbitrary code via a network packet.

Tags · CWE
Pre-auth
CWE-682
CAPEC-128
CAPEC-129
Affected products
Fedora
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2021-01-01
Published
2021-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.040 · p89
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
libtoxcoreTracked
libtoxcoreTracked
libtoxcoreTracked
libtoxcoreTracked
libtoxcoreTracked
libtoxcoreTracked
libtoxcoreTracked
libtoxcoreTracked
libtoxcoreTracked
libtoxcoreTracked
libtoxcoreTracked
libtoxcoreTracked
libtoxcoreTracked
libtoxcoreTracked
libtoxcoreTracked
libtoxcoreTracked
fedora*Tracked
toxcore*Tracked
Source databases
DEB
CVE
UBU