CVE-2012-4409
Publication date 21 November 2012
Last updated 24 July 2024
Ubuntu priority
Description
Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to execute arbitrary code via an encrypted file with a crafted header containing long salt data that is not properly handled during decryption.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| mcrypt | ||
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release | |