Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-6264

Опубликовано: 27 янв. 2017
Источник: debian

Описание

Integer signedness error in libc/string/arm/memset.S in uClibc and uClibc-ng before 1.0.16 allows context-dependent attackers to cause a denial of service (crash) via a negative length value to the memset function.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
uclibcfixed1.0.20-1package

Примечания

  • Just for cross-compiling, not used for actual packages

  • https://repo.or.cz/uclibc-ng.git/commit/e3848e3dd64a8d6437531488fe341354bc02eaed

  • http://mailman.uclibc-ng.org/pipermail/devel/2016-July/001067.html

  • Fixed in 1.0.16 of uClibc-ng

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 9 лет назад

Integer signedness error in libc/string/arm/memset.S in uClibc and uClibc-ng before 1.0.16 allows context-dependent attackers to cause a denial of service (crash) via a negative length value to the memset function.

CVSS3: 7.5
nvd
около 9 лет назад

Integer signedness error in libc/string/arm/memset.S in uClibc and uClibc-ng before 1.0.16 allows context-dependent attackers to cause a denial of service (crash) via a negative length value to the memset function.

CVSS3: 7.5
github
больше 3 лет назад

Integer signedness error in libc/string/arm/memset.S in uClibc and uClibc-ng before 1.0.16 allows context-dependent attackers to cause a denial of service (crash) via a negative length value to the memset function.