6.8
CVSSv2

CVE-2012-4527

Published: 21/11/2012 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in mcrypt 2.6.8 and previous versions allows user-assisted remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a long file name. NOTE: it is not clear whether this is a vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mcrypt mcrypt 2.6.4

mcrypt mcrypt 2.6.7

mcrypt mcrypt 2.6.5

mcrypt mcrypt

mcrypt mcrypt 2.6.6

Vendor Advisories

Debian Bug report logs - #690924 mcrypt: CVE-2012-4527 Package: mcrypt; Maintainer for mcrypt is Debian QA Group <packages@qadebianorg>; Source for mcrypt is src:mcrypt (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Fri, 19 Oct 2012 05:57:07 UTC Severity: grave Tags: patch, security ...