Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6254

Опубликовано: 26 июл. 2016
Источник: redhat
CVSS3: 8.6
CVSS2: 6.8

Описание

Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted network packet.

A heap-based buffer overflow flaw was found in collectd's network plugin. The flaw allowed a remote attacker to crash the collectd daemon (denial of service) or possibly execute remote code using a crafted network packet. For this flaw to be exploited, the network plugin must be enabled.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational ToolscollectdWill not fix
Red Hat OpenStack Platform 10 (Newton) Operational ToolscollectdNot affected
Red Hat OpenStack Platform 8 (Liberty) Operational ToolscollectdWill not fix
Red Hat OpenStack Platform 9 (Mitaka) Operational ToolscollectdWill not fix
Red Hat Storage Console 2collectdWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1360709collectd: heap overflow in the network plugin

8.6 High

CVSS3

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 9 лет назад

Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted network packet.

CVSS3: 9.1
nvd
больше 9 лет назад

Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted network packet.

CVSS3: 9.1
debian
больше 9 лет назад

Heap-based buffer overflow in the parse_packet function in network.c i ...

CVSS3: 9.1
github
больше 3 лет назад

Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted network packet.

8.6 High

CVSS3

6.8 Medium

CVSS2