CVE-2006-3251
hashcash - buffer overflow
EPSS 1.9%
Description
Heap-based buffer overflow in the array_push function in hashcash.c for Hashcash before 1.21 might allow attackers to execute arbitrary code via crafted entries.
How to fix CVE-2006-3251
To remediate CVE-2006-3251, upgrade the affected package to a fixed version below.
- Debian/hashcash—upgrade to 1.21 or later
- Debian/hashcash—upgrade to 1.17-1sarge1 or later
Is CVE-2006-3251 being exploited?
Low — EPSS is 1.9%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1.21
- from 0, < 1.17-1sarge1