CVE-2007-5197
published 2007-11-02CVE-2007-5197: Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code via unspecified…
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.62%
88.3th percentile
Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code via unspecified vectors related to Reduce in Montgomery-based Pow methods.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mono | < mono 1.2.5.1-2 (bookworm) | mono 1.2.5.1-2 (bookworm) |
| mono | mono | <= 1.2.5.1 | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | >= 0 < 1.2.5.1-2 | 1.2.5.1-2 |
| mono | mono | >= 0 < 1.2.5.1-2 | 1.2.5.1-2 |
| mono | mono | >= 0 < 1.2.5.1-2 | 1.2.5.1-2 |
| mono | mono | >= 0 < 1.2.5.1-2 | 1.2.5.1-2 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8q96-3494-9v8r: Buffer overflow in the Mono
ghsa_unreviewed·2022-05-01
CVE-2007-5197 [HIGH] CWE-119 GHSA-8q96-3494-9v8r: Buffer overflow in the Mono
Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code via unspecified vectors related to Reduce in Montgomery-based Pow methods.
OSV
CVE-2007-5197: Buffer overflow in the Mono
osv·2007-11-02·CVSS 7.5
CVE-2007-5197 [HIGH] CVE-2007-5197: Buffer overflow in the Mono
Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code via unspecified vectors related to Reduce in Montgomery-based Pow methods.
Ubuntu
Mono vulnerability
vendor_ubuntu·2007-12-04
CVE-2007-5197 Mono vulnerability
Title: Mono vulnerability
Summary: Mono vulnerability
It was discovered that Mono did not correctly bounds check certain BigInteger
actions. Remote attackers could exploit this to crash a Mono application or
possibly execute arbitrary code with user privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2007-5197: mono - Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier al...
vendor_debian·2007·CVSS 7.5
CVE-2007-5197 [HIGH] CVE-2007-5197: mono - Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier al...
Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code via unspecified vectors related to Reduce in Montgomery-based Pow methods.
Scope: local
bookworm: resolved (fixed in 1.2.5.1-2)
bullseye: resolved (fixed in 1.2.5.1-2)
forky: resolved (fixed in 1.2.5.1-2)
sid: resolved (fixed in 1.2.5.1-2)
trixie: resolved (fixed in 1.2.5.1-2)
Red Hat
: mono Math.BigInteger buffer overflow
vendor_redhat·CVSS 7.5
CVE-2007-5197 [HIGH] : mono Math.BigInteger buffer overflow
: mono Math.BigInteger buffer overflow
Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code via unspecified vectors related to Reduce in Montgomery-based Pow methods.
No detection rules found.
No public exploits indexed.
http://bugs.gentoo.org/attachment.cgi?id=134361&action=viewhttp://bugs.gentoo.org/show_bug.cgi?id=197067http://secunia.com/advisories/27439http://secunia.com/advisories/27493http://secunia.com/advisories/27511http://secunia.com/advisories/27583http://secunia.com/advisories/27612http://secunia.com/advisories/27639http://secunia.com/advisories/27937http://www.debian.org/security/2007/dsa-1397http://www.gentoo.org/security/en/glsa/glsa-200711-10.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:218http://www.novell.com/linux/security/advisories/2007_23_sr.htmlhttp://www.securityfocus.com/bid/26279http://www.securitytracker.com/id?1018892http://www.ubuntu.com/usn/usn-553-1http://www.vupen.com/english/advisories/2007/3716https://bugzilla.redhat.com/show_bug.cgi?id=367471https://exchange.xforce.ibmcloud.com/vulnerabilities/38248https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00249.htmlhttp://bugs.gentoo.org/attachment.cgi?id=134361&action=viewhttp://bugs.gentoo.org/show_bug.cgi?id=197067http://secunia.com/advisories/27439http://secunia.com/advisories/27493http://secunia.com/advisories/27511http://secunia.com/advisories/27583http://secunia.com/advisories/27612http://secunia.com/advisories/27639http://secunia.com/advisories/27937http://www.debian.org/security/2007/dsa-1397http://www.gentoo.org/security/en/glsa/glsa-200711-10.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:218http://www.novell.com/linux/security/advisories/2007_23_sr.htmlhttp://www.securityfocus.com/bid/26279http://www.securitytracker.com/id?1018892http://www.ubuntu.com/usn/usn-553-1http://www.vupen.com/english/advisories/2007/3716https://bugzilla.redhat.com/show_bug.cgi?id=367471https://exchange.xforce.ibmcloud.com/vulnerabilities/38248https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00249.html
2007-11-02
Published