CVE-2023-36328

moderate-risk
Published 2023-09-01

Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial of service (DoS).

Do I need to act?

-
0.52% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
+
Fix available
Upgrade to: 97e500351e653472b2ea00b37137ad0414165efe
9
CVSS 9.8/10 Critical
NETWORK / LOW complexity

Affected Products (4)

Libtommath

Affected Vendors

44
/ 100
moderate-risk
Severity 32/34 · Critical
Exploitability 2/34 · Minimal
Exposure 10/34 · Low