Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2016-2195

больше 10 лет назад

Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a heap-based buffer overflow. The bigint_mul and bigint_sqr functions received the size of the output buffer, but only used it to dispatch to a faster algorithm in cases where there was sufficient output space to call an unrolled multiplication function. The result is a heap overflow accessible via ECC point decoding, which accepted untrusted inputs. This is likely exploitable for remote code execution.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2016-2195

больше 10 лет назад

Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a heap-based buffer overflow.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2016-2195

больше 10 лет назад

Integer overflow in the PointGFp constructor in Botan before 1.10.11 a ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-7gxp-rgh3-mj5p

больше 4 лет назад

Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a heap-based buffer overflow.

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1222-1

больше 9 лет назад

Security update for Botan

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-2195

Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a heap-based buffer overflow. The bigint_mul and bigint_sqr functions received the size of the output buffer, but only used it to dispatch to a faster algorithm in cases where there was sufficient output space to call an unrolled multiplication function. The result is a heap overflow accessible via ECC point decoding, which accepted untrusted inputs. This is likely exploitable for remote code execution.

CVSS3: 9.8
7%
Низкий
больше 10 лет назад
nvd логотип
CVE-2016-2195

Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a heap-based buffer overflow.

CVSS3: 9.8
7%
Низкий
больше 10 лет назад
debian логотип
CVE-2016-2195

Integer overflow in the PointGFp constructor in Botan before 1.10.11 a ...

CVSS3: 9.8
7%
Низкий
больше 10 лет назад
github логотип
GHSA-7gxp-rgh3-mj5p

Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a heap-based buffer overflow.

CVSS3: 9.8
7%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2017:1222-1

Security update for Botan

больше 9 лет назад

Уязвимостей на страницу