In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsA fix was pushed into the master
branch but not yet published.
Affected versions of this package are vulnerable to Out-of-bounds Write in the bin_to_base64()
function in base64.c
. An attacker can cause memory corruption by supplying very large input to ssh_get_fingerprint_hash()
.
Note: This is only exploitable on 32-bit systems.