WikiTurk
Editor Login | Register
Ekle

> World > Security > News

Security Experts
(Date : 26.03.2008 23:45:58)


SILC Products PKSC#1 Message Buffer Overflow Vulnerability


 Reklam



Rated as : High Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2008-03-25
  A vulnerability has been identified in SILC Toolkit and SILC Client, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a buffer overflow error in the "silc_pkcs1_decode()" [silcpkcs1.c] function when decoding certain PKCS#1 messages, which could be exploited by attackers to crash an affected application or execute arbitrary code via a specially crafted signature.

Credits

Vulnerability reported by Ariel Waissbein, Pedro Varangot, Martin Mizrahi, Oren Isacson, Carlos Garcia and Ivan Arce (Core Security Technologies).



Derecelendir
Kaynak http://www.frsirt.com/english/advisories/2008/0974
İçerik İhbarı


Open Source Document Project AUP&TOS