CVE-2012-4436
EPSS 0.66%
Description
Buffer overflow in the run_last_args function in client/fwknop.c in fwknop before 2.0.3, when processing --last, might allow local users to cause a denial of service (client crash) and possibly execute arbitrary code via many .fwknop.run arguments.
How to fix CVE-2012-4436
To remediate CVE-2012-4436, upgrade the affected package to a fixed version below.
- Debian/fwknop—upgrade to 2.0.3-1 or later
Is CVE-2012-4436 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.0.3-1