First published: Sun Aug 07 2016(Updated: )
Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long string to a PR_*printf function.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netscape Portable Runtime | <=4.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1951 is considered a medium severity vulnerability due to potential buffer overflow risks.
To fix CVE-2016-1951, upgrade Netscape Portable Runtime to version 4.12 or later.
Exploitation of CVE-2016-1951 can lead to denial of service or potentially allow remote attackers to execute arbitrary code.
CVE-2016-1951 affects Netscape Portable Runtime versions prior to 4.12.
CVE-2016-1951 involves multiple integer overflow issues in the io/prprf.c component.