SB2012112205 - Multiple vulnerabilities in imipak mcrypt
Published: November 22, 2012 Updated: August 11, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Stack-based buffer overflow (CVE-ID: CVE-2012-4409)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/U:Green
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the check_file_head function in extra.c when processing an encrypted file with a crafted header containing long salt data that is not properly handled during decryption. A remote unauthenticated attacker can trigger stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
2) Format string error (CVE-ID: CVE-2012-4426)
CWE-ID: CWE-134 - Use of Externally-Controlled Format String
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Multiple format string vulnerabilities in mcrypt 2.6.8 and earlier might allow user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving (1) errors.c or (2) mcrypt.c.
3) Input validation error (CVE-ID: CVE-2012-4527)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows user-assisted remote attackers to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service (crash) and possibly execute arbitrary code via a long file name.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.
References
- http://lists.fedoraproject.org/pipermail/package-announce/2012-September/086519.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-September/087542.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-September/088281.html
- http://packetstormsecurity.org/files/116268/mcrypt-2.6.8-Buffer-Overflow-Proof-Of-Concept.html
- http://secunia.com/advisories/50507
- http://secunia.com/advisories/51010
- http://www.openwall.com/lists/oss-security/2012/09/06/4
- http://www.securitytracker.com/id?1027532
- https://bugzilla.redhat.com/show_bug.cgi?id=855029
- http://www.openwall.com/lists/oss-security/2012/09/06/8
- http://www.openwall.com/lists/oss-security/2012/09/06/9
- http://www.openwall.com/lists/oss-security/2012/09/10/5
- http://www.openwall.com/lists/oss-security/2012/09/13/22
- http://www.securityfocus.com/bid/55557
- http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091173.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091206.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-November/091377.html
- http://lists.opensuse.org/opensuse-updates/2012-11/msg00003.html
- http://www.openwall.com/lists/oss-security/2012/10/18/12
- http://www.openwall.com/lists/oss-security/2012/10/18/9
- http://www.openwall.com/lists/oss-security/2012/11/20/1
- http://www.securityfocus.com/bid/56114
- https://bugzilla.redhat.com/show_bug.cgi?id=867790