CVE-2021-44847 — Incorrect Calculation in Toxcore
Severity
9.8CRITICALNVD
EPSS
3.9%
top 11.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 13
Latest updateDec 14
Description
A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the process or potentially execute arbitrary code via a network packet.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages2 packages
Also affects: Fedora 34, 35
Patches
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2021-44847: libtoxcore - A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1...↗2021