Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2012-4409

Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to execute arbitrary code via an encrypted file with a crafted header containing long salt data that is not properly handled during decryption.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.587
EPSS Ranking 98.1%
CVSS Severity
CVSS v2 Score 6.8
References
Products affected by CVE-2012-4409
  • Mcrypt » Mcrypt » Version: Any
    cpe:2.3:a:mcrypt:mcrypt:*
  • Mcrypt » Mcrypt » Version: 2.6.4
    cpe:2.3:a:mcrypt:mcrypt:2.6.4
  • Mcrypt » Mcrypt » Version: 2.6.5
    cpe:2.3:a:mcrypt:mcrypt:2.6.5
  • Mcrypt » Mcrypt » Version: 2.6.6
    cpe:2.3:a:mcrypt:mcrypt:2.6.6
  • Mcrypt » Mcrypt » Version: 2.6.7
    cpe:2.3:a:mcrypt:mcrypt:2.6.7


Contact Us

Shodan ® - All rights reserved