CVE-2016-2054: Buffer Overflow
Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long filename, involving handling a "config" command.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2054?
CVE-2016-2054 is classified as a high severity vulnerability due to the potential for remote code execution and denial of service.
How do I fix CVE-2016-2054?
To fix CVE-2016-2054, upgrade Xymon to version 4.3.25 or later.
Who is affected by CVE-2016-2054?
CVE-2016-2054 affects multiple versions of Xymon from 4.1.x to 4.3.x prior to 4.3.25.
What types of attacks can exploit CVE-2016-2054?
CVE-2016-2054 can be exploited by attackers to execute arbitrary code or crash the daemon through crafted long filenames.
What software is associated with CVE-2016-2054?
CVE-2016-2054 is associated with Xymon versions 4.1.x, 4.2.x, and 4.3.x before 4.3.25, including specific Debian Linux distributions.