First published: Mon Sep 28 2015(Updated: )
Buffer overflow in the DumpSysVar function in var.c in Remind before 3.1.15 allows attackers to have unspecified impact via a long name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE | =13.1 | |
openSUSE | =13.2 | |
Roaring Penguin Remind | <=3.1.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5957 is considered a moderate severity vulnerability due to the buffer overflow that can lead to unspecified impacts.
To fix CVE-2015-5957, update Remind to version 3.1.15 or later and ensure that you are using supported versions of openSUSE.
CVE-2015-5957 may allow attackers to exploit the buffer overflow, potentially leading to arbitrary code execution or denial of service.
CVE-2015-5957 affects Remind versions prior to 3.1.15 and specific versions of openSUSE, namely 13.1 and 13.2.
Yes, CVE-2015-5957 can potentially be exploited remotely if the attacker can send specially crafted data to the affected application.