UBUNTU-CVE-2023-36328
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-36328
UBUNTU-CVE-2023-36328
Summary:
Details: Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial of service (DoS).
References: https://ubuntu.com/security/CVE-2023-36328, https://github.com/libtom/libtommath/pull/546, https://github.com/libtom/libtommath/commit/beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, https://lists.fedoraproject.org/archives/list/[email protected]/message/3H2PFUTBKQUDSOJXQQS7LUSZQWT3JTW2/, https://ubuntu.com/security/notices/USN-6402-1, https://ubuntu.com/security/notices/USN-6402-2, https://www.cve.org/CVERecord?id=CVE-2023-36328
Affected packages
Package
Name: libtommath
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
