Bug 521257 (CVE-2008-7159) - CVE-2008-7159 libsilc: stack corruption during ASN1 encoding of OID
Summary: CVE-2008-7159 libsilc: stack corruption during ASN1 encoding of OID
Alias: CVE-2008-7159
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On:
TreeView+ depends on / blocked
Reported: 2009-09-04 14:53 UTC by Tomas Hoger
Modified: 2021-11-12 19:54 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2009-09-04 14:54:11 UTC

Attachments (Terms of Use)

Description Tomas Hoger 2009-09-04 14:53:04 UTC
SILC Toolkit 1.1.8 fixed following issue:


    ASN1: Fix stack variable overwrite when encoding OID.
    The call to sscanf specifies a format string of "%lu", a long unsigned
    int.  The pointer argument was cast to unsigned long *, but this is
    wrong for 64 bit systems.  On 64 bit systems, unsigned long is 64 bits,
    but the oid value is a SilcUInt32 on all systems.  As a result, sscanf
    will overwrite a neighboring variable on the stack.  Fix this by
    changing the format string to "%u" and removing the cast.

Upstream fix:

This problem is already fixed in Fedora libsilc packages, which are based on fixed 1.1.8 version.

Version of libsilc shipped in Red Hat Enterprise Linux 4 and 5 do not contain affected code and hence are not affected by this problem.

Note You need to log in before you can comment on or make changes to this bug.