Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-1552
Description:The silc_pkcs1_decode function in the silccrypt library (silcpkcs1.c) in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.7, SILC Client before 1.1.4, and SILC Server before 1.1.2 allows remote attackers to execute arbitrary code via a crafted PKCS#1 message, which triggers an integer underflow, signedness error, and a buffer overflow. NOTE: the researcher describes this as an integer overflow, but CVE uses the "underflow" term in cases of wraparound from unsigned subtraction.
Test IDs: 1.3.6.1.4.1.25623.1.0.860836   1.3.6.1.4.1.25623.1.0.860341   1.3.6.1.4.1.25623.1.0.60631  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-1552
BugTraq ID: 28373
http://www.securityfocus.com/bid/28373
Bugtraq: 20080325 CORE-2007-1212: SILC pkcs_decode buffer overflow (Google Search)
http://www.securityfocus.com/archive/1/490069/100/0/threaded
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00513.html
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00538.html
http://security.gentoo.org/glsa/glsa-200804-27.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2008:158
http://www.coresecurity.com/?action=item&id=2206
http://www.securitytracker.com/id?1019690
http://secunia.com/advisories/29463
http://secunia.com/advisories/29465
http://secunia.com/advisories/29622
http://secunia.com/advisories/29946
http://securityreason.com/securityalert/3795
SuSE Security Announcement: SUSE-SR:2008:008 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html
http://www.vupen.com/english/advisories/2008/0974/references
XForce ISS Database: silc-silcpkcs1decode-bo(41474)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41474




© 1998-2025 E-Soft Inc. All rights reserved.