Vulnerability Description
Integer Overflow vulnerability in RELIC before commit 421f2e91cf2ba42473d4d54daf24e295679e290e, allows attackers to execute arbitrary code and cause a denial of service in pos argument in bn_get_prime function.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Relic Project | Relic | < 2022-11-14 |
Related Weaknesses (CWE)
References
- https://github.com/relic-toolkit/relic/commit/421f2e91cf2ba42473d4d54daf24e29567Patch
- https://groups.google.com/g/relic-discuss/c/A_J2-ArVIAo/m/qgFiXsUJBQAJ?utm_mediuMailing List
- https://github.com/relic-toolkit/relic/commit/421f2e91cf2ba42473d4d54daf24e29567Patch
- https://groups.google.com/g/relic-discuss/c/A_J2-ArVIAo/m/qgFiXsUJBQAJ?utm_mediuMailing List
FAQ
What is CVE-2023-36327?
CVE-2023-36327 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Integer Overflow vulnerability in RELIC before commit 421f2e91cf2ba42473d4d54daf24e295679e290e, allows attackers to execute arbitrary code and cause a denial of service in pos argument in bn_get_prime...
How severe is CVE-2023-36327?
CVE-2023-36327 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-36327?
Check the references section above for vendor advisories and patch information. Affected products include: Relic Project Relic.