CVE-2012-4426
EPSS 4.7%
Description
Multiple format string vulnerabilities in mcrypt 2.6.8 and earlier might allow user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving (1) errors.c or (2) mcrypt.c.
How to fix CVE-2012-4426
To remediate CVE-2012-4426, upgrade the affected package to a fixed version below.
- Debian/mcrypt—upgrade to 2.6.8-1.1 or later
Is CVE-2012-4426 being exploited?
Low — EPSS is 4.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.6.8-1.1