CVE-2016-1234: Buffer Overflow
Published Jun 1, 2016
·Updated
Last updated 24 July 2024
Other sources
Stack-based buffer overflow in the glob implementation in GNU C Library (aka glibc) before 2.24, when GLOBALTDIRFUNC is used, allows context-dependent attackers to cause a denial of service (crash) via a long name.
— Launchpad
Affected Software
5 affected componentsFixes available
GNU glibc<2.24
openSUSE Leap=42.1
openSUSE openSUSE=13.2
Fedoraproject Fedora=23
debian/glibc
2.31-13+deb11u112.31-13+deb11u102.36-9+deb12u102.36-9+deb12u72.41-7
Remediation
Event History
Jun 1, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:15 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:10 AM
RemedyDescriptionSeverityAffected Software
Mar 31, 2025
Data Sourced
via Debian·03:26 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-1234?
CVE-2016-1234 is rated as a high-severity vulnerability due to the potential for denial of service.
2
How do I fix CVE-2016-1234?
To fix CVE-2016-1234, update the GNU C Library (glibc) to version 2.24 or later.
3
Which systems are affected by CVE-2016-1234?
CVE-2016-1234 affects glibc versions prior to 2.24, including specific versions on openSUSE and Fedora.
4
What type of vulnerability is CVE-2016-1234?
CVE-2016-1234 is a stack-based buffer overflow vulnerability.
5
Can CVE-2016-1234 be exploited remotely?
CVE-2016-1234 can be exploited by context-dependent attackers, potentially allowing remote denial of service.