Bug 1214927 (CVE-2023-36328) - VUL-0: CVE-2023-36328: libtommath: integer overflow vulnerability in mp_grow in libtom
Summary: VUL-0: CVE-2023-36328: libtommath: integer overflow vulnerability in mp_grow ...
Status: NEW
Alias: CVE-2023-36328
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: Michal Kubeček
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/376983/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-36328:7.8:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-09-04 07:42 UTC by Alexander Bergmann
Modified: 2024-02-05 06:02 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---
stoyan.manolov: needinfo? (mkubecek)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2023-09-04 07:42:28 UTC
CVE-2023-36328

Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial of service (DoS).

https://github.com/libtom/libtommath/pull/546

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-36328
https://bugzilla.redhat.com/show_bug.cgi?id=2236877
https://www.cve.org/CVERecord?id=CVE-2023-36328
https://github.com/libtom/libtommath/pull/546
Comment 2 OBSbugzilla Bot 2023-11-15 09:15:02 UTC
This is an autogenerated message for OBS integration:
This bug (1214927) was mentioned in
https://build.opensuse.org/request/show/1126546 Factory / libtommath