CVE-2012-4409
EPSS 15.0%
Description
Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to execute arbitrary code via an encrypted file with a crafted header containing long salt data that is not properly handled during decryption.
How to fix CVE-2012-4409
To remediate CVE-2012-4409, upgrade the affected package to a fixed version below.
- Debian/mcrypt—upgrade to 2.6.8-1.1 or later
Is CVE-2012-4409 being exploited?
Moderate — EPSS is 15.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2.6.8-1.1