{"api_version":"1","generated_at":"2026-07-23T12:57:22+00:00","cve":"CVE-2021-44847","urls":{"html":"https://cve.report/CVE-2021-44847","api":"https://cve.report/api/cve/CVE-2021-44847.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-44847","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-44847"},"summary":{"title":"CVE-2021-44847","description":"A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the process or potentially execute arbitrary code via a network packet.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-12-13 01:15:00","updated_at":"2023-11-07 03:39:00"},"problem_types":["CWE-682"],"metrics":[],"references":[{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S7EBS3NIRYJ7V3PTNINP3PJSVUHGZTGA/","name":"FEDORA-2021-8026e9b394","refsource":"","tags":[],"title":"[SECURITY] Fedora 35 Update: toxcore-0.2.13-1.fc35 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLTKINSPO5T65LB3ZASDPCREKUE22RYE/","name":"FEDORA-2021-8b746a32c5","refsource":"","tags":[],"title":"[SECURITY] Fedora 34 Update: toxcore-0.2.13-1.fc34 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLTKINSPO5T65LB3ZASDPCREKUE22RYE/","name":"FEDORA-2021-8b746a32c5","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 34 Update: toxcore-0.2.13-1.fc34 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S7EBS3NIRYJ7V3PTNINP3PJSVUHGZTGA/","name":"FEDORA-2021-8026e9b394","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 35 Update: toxcore-0.2.13-1.fc35 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/TokTok/c-toxcore/pull/1718","name":"https://github.com/TokTok/c-toxcore/pull/1718","refsource":"MISC","tags":[],"title":"fix: Sec/fix crypto size compute by sudden6 · Pull Request #1718 · TokTok/c-toxcore · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-44847","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-44847","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"44847","vulnerable":"1","versionEndIncluding":"0.1.11","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"digitalocean","cpe5":"toxcore","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"44847","vulnerable":"1","versionEndIncluding":"0.2.12","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"digitalocean","cpe5":"toxcore","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"44847","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"34","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"44847","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"35","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"44847","vulnerable":"1","versionEndIncluding":"0.1.11","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"toktok","cpe5":"toxcore","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"44847","vulnerable":"1","versionEndIncluding":"0.2.12","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"toktok","cpe5":"toxcore","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-44847","qid":"183946","title":"Debian Security Update for libtoxcore (CVE-2021-44847)"},{"cve":"CVE-2021-44847","qid":"282197","title":"Fedora Security Update for toxcore (FEDORA-2021-8b746a32c5)"},{"cve":"CVE-2021-44847","qid":"282199","title":"Fedora Security Update for toxcore (FEDORA-2021-8026e9b394)"},{"cve":"CVE-2021-44847","qid":"710883","title":"Gentoo Linux Tox Remote Code Execution (RCE) Vulnerability (GLSA 202403-01)"},{"cve":"CVE-2021-44847","qid":"751569","title":"OpenSUSE Security Update for c-toxcore (openSUSE-SU-2021:1640-1)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-44847","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the process or potentially execute arbitrary code via a network packet."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/TokTok/c-toxcore/pull/1718","refsource":"MISC","name":"https://github.com/TokTok/c-toxcore/pull/1718"},{"refsource":"FEDORA","name":"FEDORA-2021-8026e9b394","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S7EBS3NIRYJ7V3PTNINP3PJSVUHGZTGA/"},{"refsource":"FEDORA","name":"FEDORA-2021-8b746a32c5","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLTKINSPO5T65LB3ZASDPCREKUE22RYE/"}]}},"nvd":{"publishedDate":"2021-12-13 01:15:00","lastModifiedDate":"2023-11-07 03:39:00","problem_types":["CWE-682"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:toktok:toxcore:*:*:*:*:*:*:*:*","versionStartIncluding":"0.2.0","versionEndIncluding":"0.2.12","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:toktok:toxcore:*:*:*:*:*:*:*:*","versionStartIncluding":"0.1.9","versionEndIncluding":"0.1.11","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"44847","Ordinal":"222714","Title":"CVE-2021-44847","CVE":"CVE-2021-44847","Year":"2021"},"notes":[]}}}