CVE-2020-12651

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
15/05/2020
Last modified:
08/09/2021

Description

SecureCRT before 8.7.2 allows remote attackers to execute arbitrary code via an Integer Overflow and a Buffer Overflow because a banner can trigger a line number to CSI functions that exceeds INT_MAX.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vandyke:securecrt:*:*:*:*:*:*:*:* 8.7.2 (excluding)
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:vandyke:securecrt:*:*:*:*:*:*:*:* 2.4 (excluding)
cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*