CVE-2016-2147: Integer Overflow
Published Feb 9, 2017
·Updated
Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.
Affected Software
8 affected componentsFixes available
Busybox Busybox<=1.24.2
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
debian/busybox
1:1.30.1-61:1.30.1-6+deb11u11:1.35.0-4+deb12u11:1.37.0-61:1.37.0-10.1
Remediation
Patch Available
Event History
Feb 9, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:15 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·12:41 AM
RemedyDescriptionSeverityAffected Software
May 18, 2026
Data Sourced
via Debian·03:28 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2016-2147.
2
What is the severity of CVE-2016-2147?
The severity of CVE-2016-2147 is high with a severity value of 7.5.
3
How does CVE-2016-2147 impact the affected software?
CVE-2016-2147 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.
4
Which versions of BusyBox are affected by CVE-2016-2147?
Versions up to and including 1.24.2 of BusyBox are affected by CVE-2016-2147.
5
How can I fix CVE-2016-2147?
To fix CVE-2016-2147, update BusyBox to version 1.25.0 or higher.