The silc_pkcs1_decode function in the silccrypt library (silcpkcs1.c) in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.7, SILC Client before 1.1.4, and SILC Server before 1.1.2 allows remote attackers to execute arbitrary code via a crafted PKCS#1 message, which triggers an integer underflow, signedness error, and a buffer overflow. NOTE: the researcher describes this as an integer overflow, but CVE uses the "underflow" term in cases of wraparound from unsigned subtraction.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2008-03-31T17:00:00

Updated: 2018-10-11T19:57:01

Reserved: 2008-03-31T00:00:00


Link: CVE-2008-1552

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2008-03-31T17:44:00.000

Modified: 2018-10-11T20:35:27.787


Link: CVE-2008-1552

JSON object: View

cve-icon Redhat Information

No data.

CWE