CVE-2016-4021: High severity red hat fedora vulnerability
Published May 26, 2016
·Updated
The readbinary function in buffer.c in pgpdump before 0.30 allows context-dependent attackers to cause a denial of service (infinite loop and CPU consumption) via crafted input, as demonstrated by the \xa3\x03 string.
Affected Software
4 affected components
Fedoraproject Fedora=22
Fedoraproject Fedora=23
Fedoraproject Fedora=24
Pgpdump Project Pgpdump<=0.29
Event History
May 26, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4021?
CVE-2016-4021 has been classified as a denial of service vulnerability due to its ability to cause CPU exhaustion.
2
How do I fix CVE-2016-4021?
To mitigate CVE-2016-4021, upgrade pgpdump to version 0.30 or later.
3
Which software versions are affected by CVE-2016-4021?
CVE-2016-4021 affects pgpdump versions prior to 0.30 and Fedora releases 22, 23, and 24.
4
What impact does CVE-2016-4021 have on systems?
CVE-2016-4021 can lead to an infinite loop and excessive CPU consumption, potentially disrupting service availability.
5
Who can exploit CVE-2016-4021?
CVE-2016-4021 can be exploited by context-dependent attackers using specially crafted input.