CVE-2023-36328
moderate-risk
Published 2023-09-01
Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial of service (DoS).
Do I need to act?
-
0.52% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
+
Fix available
Upgrade to: 97e500351e653472b2ea00b37137ad0414165efe
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Vendors
References (9)
Issue Tracking
https://github.com/libtom/libtommath/pull/546
Issue Tracking
https://github.com/libtom/libtommath/pull/546
44
/ 100
moderate-risk
Severity
32/34 · Critical
Exploitability
2/34 · Minimal
Exposure
10/34 · Low