CVE-2008-1552

The silc_pkcs1_decode function in the silccrypt library (silcpkcs1.c) in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.7, SILC Client before 1.1.4, and SILC Server before 1.1.2 allows remote attackers to execute arbitrary code via a crafted PKCS#1 message, which triggers an integer underflow, signedness error, and a buffer overflow. NOTE: the researcher describes this as an integer overflow, but CVE uses the "underflow" term in cases of wraparound from unsigned subtraction.

Published: 2008-03-31 Last update: 2026-04-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2008-1552 is rated Moderate Risk (57/100): CVSS Medium severity, with high exploitation likelihood (EPSS 6.73%, 91th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2008-1552

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-05-21 8.69% 6.73% -1.96%
2 2025-03-30 12.51% 8.69% -3.82%
3 2025-03-29 12.51%

Full EPSS history (13 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2008-1552

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.8 2.0 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
8.6 6.4 [email protected]

Weakness enumeration for CVE-2008-1552

OS Trackers for CVE-2008-1552

vendor priority summary link
gentoo normal CVE-2008-1552: 1 GLSA(s) (200804-27), 3 atom(s) (net-im/silc-client, net-im/silc-server, net-im/silc-toolkit); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2008-1552
redhat medium https://access.redhat.com/security/cve/CVE-2008-1552
ubuntu medium CVE-2008-1552 medium priority: Ubuntu including 1 source packages (silc-client), 13 status rows across 13 suites (dapper, edgy, feisty, gutsy, hardy, intrepid, jaunty, karmic, lucid, maverick, natty, oneiric, upstream): not-affected 7, DNE 3, ignored 2, released 1. https://ubuntu.com/security/CVE-2008-1552

Vendor comments (NVD) for CVE-2008-1552

  • Red Hat (2008-04-23T00:00:00)

    Red Hat does not consider this issue to be a security flaw as SILC is not used in a vulnerable manner in Red Hat Enterprise Linux 4 and 5. More information can be found here: https://bugzilla.redhat.com/show_bug.cgi?id=440049

Affected software / configurations for CVE-2008-1552

Vendor Product Version Raw CPE
silc silc_client <= 1.1.3 cpe:2.3:a:silc:silc_client:*:*:*:*:*:*:*:*
silc silc_server <= 1.1.2 cpe:2.3:a:silc:silc_server:*:*:*:*:*:*:*:*
silc silc_toolkit <= 1.1.6 cpe:2.3:a:silc:silc_toolkit:*:*:*:*:*:*:*:*
silc silc cpe:2.3:a:silc:silc:*:*:*:*:*:*:*:*

References for CVE-2008-1552

URL Tags
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html
http://secunia.com/advisories/29463 Vendor Advisory
http://secunia.com/advisories/29465
http://secunia.com/advisories/29622
http://secunia.com/advisories/29946
http://security.gentoo.org/glsa/glsa-200804-27.xml
http://securityreason.com/securityalert/3795
http://silcnet.org/general/news/?item=client_20080320_1 Patch
http://silcnet.org/general/news/?item=server_20080320_1 Patch
http://silcnet.org/general/news/?item=toolkit_20080320_1 Patch
http://www.coresecurity.com/?action=item&id=2206
http://www.mandriva.com/security/advisories?name=MDVSA-2008:158
http://www.securityfocus.com/archive/1/490069/100/0/threaded
http://www.securityfocus.com/bid/28373 Patch
http://www.securitytracker.com/id?1019690
http://www.vupen.com/english/advisories/2008/0974/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/41474
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00513.html
https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00538.html
cvelogic Threat Intelligence