CVE-2008-1552

NameCVE-2008-1552
DescriptionThe silc_pkcs1_decode function in the silccrypt library (silcpkcs1.c) in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.7, SILC Client before 1.1.4, and SILC Server before 1.1.2 allows remote attackers to execute arbitrary code via a crafted PKCS#1 message, which triggers an integer underflow, signedness error, and a buffer overflow. NOTE: the researcher describes this as an integer overflow, but CVE uses the "underflow" term in cases of wraparound from unsigned subtraction.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
silc-clientsource(unstable)(not affected)
silc-toolkitsource(unstable)1.1.7-1low

Notes

- silc-client <not-affected> (links against libsilc)
this can't result code execution but only in a crash as data_len - i always results
in -1 and malloc will never succeed and thus not reaching any free

Search for package or bug name: Reporting problems