Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4353

Опубликовано: 08 апр. 2015
Источник: redhat
CVSS2: 2.6

Описание

ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (abort) via crafted BER data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libksbaWill not fix
Red Hat Enterprise Linux 6libksbaWill not fix
Red Hat Enterprise Linux 7libksbaWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1211261libksba: denial of service due to stack overflow in src/ber-decoder.c (push_decoder_state, pop_decoder_state)

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (abort) via crafted BER data.

CVSS3: 7.5
nvd
больше 9 лет назад

ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (abort) via crafted BER data.

CVSS3: 7.5
debian
больше 9 лет назад

ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder ...

CVSS3: 7.5
github
больше 3 лет назад

ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (abort) via crafted BER data.

2.6 Low

CVSS2