CVE-2012-4527
EPSS 7.7%
Description
Stack-based buffer overflow in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long file name. NOTE: it is not clear whether this is a vulnerability.
How to fix CVE-2012-4527
To remediate CVE-2012-4527, upgrade the affected package to a fixed version below.
- Debian/mcrypt—upgrade to 2.6.8-1.3 or later
Is CVE-2012-4527 being exploited?
Moderate — EPSS is 7.7%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2.6.8-1.3