CVE-2021-44847
Summary
| CVE | CVE-2021-44847 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-13 01:15:00 UTC |
| Updated | 2023-11-07 03:39:00 UTC |
| Description | A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the process or potentially execute arbitrary code via a network packet. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 35 Update: toxcore-0.2.13-1.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: toxcore-0.2.13-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: toxcore-0.2.13-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: toxcore-0.2.13-1.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| fix: Sec/fix crypto size compute by sudden6 · Pull Request #1718 · TokTok/c-toxcore · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 183946 Debian Security Update for libtoxcore (CVE-2021-44847)
- 282197 Fedora Security Update for toxcore (FEDORA-2021-8b746a32c5)
- 282199 Fedora Security Update for toxcore (FEDORA-2021-8026e9b394)
- 710883 Gentoo Linux Tox Remote Code Execution (RCE) Vulnerability (GLSA 202403-01)
- 751569 OpenSUSE Security Update for c-toxcore (openSUSE-SU-2021:1640-1)