Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-6318

Опубликовано: 07 сент. 2016
Источник: debian

Описание

Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges via a long GECOS field, involving longbuffer.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cracklib2fixed2.9.2-2package

Примечания

  • https://bugzilla.redhat.com/attachment.cgi?id=1188599

  • In Debian compiled with CPPFLAGS="-D_FORTIFY_SOURCE=2" so, at most application crash

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 9 лет назад

Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges via a long GECOS field, involving longbuffer.

CVSS3: 4
redhat
больше 9 лет назад

Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges via a long GECOS field, involving longbuffer.

CVSS3: 7.8
nvd
больше 9 лет назад

Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges via a long GECOS field, involving longbuffer.

suse-cvrf
больше 9 лет назад

Security update for cracklib

suse-cvrf
больше 9 лет назад

Security update for cracklib