CVE-2016-10079: Input Validation
Published Feb 1, 2017
·Updated
SAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long string to TCP port 515.
Affected Software
1 affected component
SAP SAPlpd<=7400.3.11.33
Event History
Feb 1, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-10079?
CVE-2016-10079 is classified as a Denial of Service vulnerability which can cause a service crash.
2
How do I fix CVE-2016-10079?
To fix CVE-2016-10079, upgrade to a version of SAP LPD higher than 7400.3.11.33.
3
What systems are affected by CVE-2016-10079?
CVE-2016-10079 affects SAP LPd versions up to and including 7400.3.11.33 on Windows.
4
What can an attacker achieve with CVE-2016-10079?
An attacker can exploit CVE-2016-10079 to send a long string to TCP port 515, resulting in a Denial of Service.
5
Is CVE-2016-10079 easy to exploit?
CVE-2016-10079 can be easily exploited by sending a specially crafted long string to the vulnerable service.