Vulnerability Description
Integer Overflow vulnerability in RELIC before commit 34580d840469361ba9b5f001361cad659687b9ab, allows attackers to execute arbitrary code, cause a denial of service, and escalate privileges when calling realloc function in bn_grow function.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Relic Project | Relic | < 2022-11-14 |
Related Weaknesses (CWE)
References
- https://github.com/relic-toolkit/relic/commit/34580d840469361ba9b5f001361cad6596Patch
- https://groups.google.com/g/relic-discuss/c/A_J2-ArVIAo/m/qgFiXsUJBQAJ?utm_mediuMailing List
- https://github.com/relic-toolkit/relic/commit/34580d840469361ba9b5f001361cad6596Patch
- https://groups.google.com/g/relic-discuss/c/A_J2-ArVIAo/m/qgFiXsUJBQAJ?utm_mediuMailing List
FAQ
What is CVE-2023-36326?
CVE-2023-36326 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Integer Overflow vulnerability in RELIC before commit 34580d840469361ba9b5f001361cad659687b9ab, allows attackers to execute arbitrary code, cause a denial of service, and escalate privileges when call...
How severe is CVE-2023-36326?
CVE-2023-36326 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-36326?
Check the references section above for vendor advisories and patch information. Affected products include: Relic Project Relic.