VDB
CVE-2008-1552
CVE-2008-1552
PUBLISHED
CVSS 6.800000190734863 MEDIUM
The silc_pkcs1_decode function in the silccrypt library (silcpkcs1.c) in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.7, SILC Client before 1.1.4, and SILC Server before 1.1.2 allows remote attackers to execute arbitrary code via a crafted PKCS#1 message, which triggers an integer underflow, signedness error, and a buffer overflow. NOTE: the researcher describes this as an integer overflow, but CVE uses the "underflow" term in cases of wraparound from unsigned subtraction.
EPSS 6.73% · 91.5th percentile
Risk Scores
CVSS 2.0
6.800000190734863
EPSS Score
6.73%
91.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| silc | silc | |
| silc | silc_server | 0 |
| silc | silc_toolkit | 0 |
| silc | silc_client | 0 |
| n/a | n/a | * |
Timeline
- Mar 31, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
References
- http://secunia.com/advisories/29463 advisory
- 29465 third-party-advisory
- 29622 third-party-advisory
- SUSE-SR:2008:008 vendor-advisory
- 1019690 vdb
- GLSA-200804-27 vendor-advisory
- 3795 third-party-advisory
- http://silcnet.org/general/news/?item=server_20080320_1 url
- 20080325 CORE-2007-1212: SILC pkcs_decode buffer overflow mailing-list
- http://silcnet.org/general/news/?item=toolkit_20080320_1 url
- FEDORA-2008-2641 vendor-advisory
- ADV-2008-0974 vdb
- 29946 third-party-advisory
- 28373 vdb
- http://www.coresecurity.com/?action=item&id=2206 url
- http://silcnet.org/general/news/?item=client_20080320_1 url
- MDVSA-2008:158 vendor-advisory
- silc-silcpkcs1decode-bo(41474) vdb
- FEDORA-2008-2616 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2008-1552 advisory