CVE-2016-1951: Buffer Overflow
Published Aug 7, 2016
·Updated
Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long string to a PRprintf function.
Affected Software
1 affected component
Mozilla Netscape Portable Runtime<=4.11
Event History
Aug 7, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1951?
CVE-2016-1951 is considered a medium severity vulnerability due to potential buffer overflow risks.
2
How do I fix CVE-2016-1951?
To fix CVE-2016-1951, upgrade Netscape Portable Runtime to version 4.12 or later.
3
What happens if CVE-2016-1951 is exploited?
Exploitation of CVE-2016-1951 can lead to denial of service or potentially allow remote attackers to execute arbitrary code.
4
Which versions of Netscape Portable Runtime are affected by CVE-2016-1951?
CVE-2016-1951 affects Netscape Portable Runtime versions prior to 4.12.
5
What components of Netscape Portable Runtime are involved in CVE-2016-1951?
CVE-2016-1951 involves multiple integer overflow issues in the io/prprf.c component.