CVE-2016-0264: Buffer Overflow
A buffer overflow flaw was fixed in IBM JDK 6 SR16-FP25, 7 SR9-FP40, 7R1 SR3-FP40, and 8 SR3:
CVEID: CVE-2016-0264 DESCRIPTION: A buffer overflow vulnerability in the IBM JVM facilitates arbitrary code execution under certain limited circumstances. CVSS Base Score: 5.6 CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
http://www-01.ibm.com/support/docview.wss?uid=swg21980826
External Reference:
http://www.ibm.com/developerworks/java/jdk/alerts/#IBMSecurityUpdateApril2016
Other sources
Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) allows remote attackers to execute arbitrary code via unspecified vectors.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2016-0264?
CVE-2016-0264 has been classified as a high severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2016-0264?
To fix CVE-2016-0264, update to the patched versions for IBM JDK and related products as specified in the official advisory.
What types of systems are affected by CVE-2016-0264?
CVE-2016-0264 affects various versions of IBM JDK running on Linux distributions like Red Hat and SUSE.
Can CVE-2016-0264 be exploited remotely?
Yes, CVE-2016-0264 can be exploited remotely if the vulnerable application is exposed to untrusted inputs.
What happens if CVE-2016-0264 is exploited successfully?
If exploited successfully, CVE-2016-0264 allows attackers to execute arbitrary code on the affected system.