CVE-2016-10188: Use After Free
Published Mar 14, 2017
·Updated
Use-after-free vulnerability in bitlbee-libpurple before 3.5 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code by causing a file transfer connection to expire.
Affected Software
1 affected component
bitlbee BitlBee<=3.4.2
Remediation
Patch Available
Patch Available
Patch Available
Event History
Mar 14, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10188?
CVE-2016-10188 has a severity rating that could lead to denial of service or potential remote code execution.
2
How can I fix CVE-2016-10188?
To fix CVE-2016-10188, update Bitlbee to version 3.5 or later.
3
What causes the CVE-2016-10188 vulnerability?
CVE-2016-10188 is caused by a use-after-free condition in the bitlbee-libpurple component during file transfer connections.
4
Who is affected by CVE-2016-10188?
CVE-2016-10188 affects users of Bitlbee versions prior to 3.5.
5
What are the potential impacts of CVE-2016-10188?
The impacts of CVE-2016-10188 include application crashes and possible arbitrary code execution.