Tox: Remote Code Execution A vulnerability has been discovered in Tox which may lead to remote code execution. tox 2024-03-03 2024-03-03 829650 remote 0.2.13 0.2.13

Tox is easy-to-use software that connects you with friends and family without anyone else listening in.

A vulnerability has been discovered in btrbk. Please review the CVE identifier referenced below for details.

A stack-based buffer overflow allows remote attackers to crash the process or potentially execute arbitrary code via a network packet.

There is no known workaround at this time.

All Tox users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-libs/tox-0.2.13"
CVE-2021-44847 graaff graaff