CVE-2007-5197Improper Restriction of Operations within the Bounds of a Memory Buffer in Mono

Severity
7.5HIGHNVD
EPSS
2.3%
top 15.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 2
Latest updateMay 1

Description

Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code via unspecified vectors related to Reduce in Montgomery-based Pow methods.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/mono< mono 1.2.5.1-2 (bookworm)
Debianmono/mono< 1.2.5.1-2+3
NVDmono/mono1.2.5.1+11

🔴Vulnerability Details

3
GHSA
GHSA-8q96-3494-9v8r: Buffer overflow in the Mono2022-05-01
CVEList
CVE-2007-5197: Buffer overflow in the Mono2007-11-02
OSV
CVE-2007-5197: Buffer overflow in the Mono2007-11-02

📋Vendor Advisories

3
Ubuntu
Mono vulnerability2007-12-04
Debian
CVE-2007-5197: mono - Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier al...2007
Red Hat
: mono Math.BigInteger buffer overflow

💬Community

1
Bugzilla
CVE-2007-5197: mono Math.BigInteger buffer overflow2007-11-05