CVE-2023-36328
Summary
| CVE | CVE-2023-36328 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-01 16:15:00 UTC |
| Updated | 2023-11-07 04:16:00 UTC |
| Description | Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial of service (DoS). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 37 Update: libtommath-1.2.0-11.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Fix possible integer overflow by czurnieden · Pull Request #546 · libtom/libtommath · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 39 Update: libtommath-1.2.0-13.fc39 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: libtommath-1.2.0-11.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 39 Update: libtommath-1.2.0-13.fc39 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 38 Update: libtommath-1.2.0-12.fc38 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 38 Update: libtommath-1.2.0-12.fc38 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199792 Ubuntu Security Notification for LibTomMath Vulnerability (USN-6402-1)
- 199953 Ubuntu Security Notification for LibTomMath Vulnerability (USN-6402-2)
- 284525 Fedora Security Update for libtommath (FEDORA-2023-f5680e3b4b)
- 285271 Fedora Security Update for libtommath (FEDORA-2023-f357a25877)
- 356242 Amazon Linux Security Advisory for libtommath : ALASANSIBLE2-2023-010
- 356379 Amazon Linux Security Advisory for libtommath : ALAS2023-2023-370
- 356465 Amazon Linux Security Advisory for libtommath : ALAS2ANSIBLE2-2023-010
- 673326 EulerOS Security Update for libtommath (EulerOS-SA-2024-1278)
- 673355 EulerOS Security Update for libtommath (EulerOS-SA-2023-3014)
- 673409 EulerOS Security Update for libtommath (EulerOS-SA-2023-3185)
- 673467 EulerOS Security Update for libtommath (EulerOS-SA-2023-3037)
- 673468 EulerOS Security Update for libtommath (EulerOS-SA-2023-3340)
- 673761 EulerOS Security Update for libtommath (EulerOS-SA-2023-3220)
- 673978 EulerOS Security Update for libtommath (EulerOS-SA-2023-3308)
- 907298 Common Base Linux Mariner (CBL-Mariner) Security Update for libtommath (28639-1)
- 907336 Common Base Linux Mariner (CBL-Mariner) Security Update for tcl (28627-1)