ELA-1167-1 libtommath security update

integer overflow vulnerabilities

2024-08-28
Packagelibtommath
Version0.42.0-1.1+deb8u1 (jessie), 1.0-4+deb9u1 (stretch), buster (1.1.0-3+deb10u1)
Related CVEs CVE-2023-36328


It was discovered that there was a series of integer overflow vulnerabilities in LibTomMath, a multiple-precision mathematics library.

This could have led attackers to execute arbitrary code and/or cause a denial of service (DoS).



For Debian 10 buster, these problems have been fixed in version 1.1.0-3+deb10u1.

For Debian 8 jessie, these problems have been fixed in version 0.42.0-1.1+deb8u1.

For Debian 9 stretch, these problems have been fixed in version 1.0-4+deb9u1.

We recommend that you upgrade your libtommath packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.