CVE-2016-4353: Input Validation
Published Jun 13, 2016
·Updated
ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (abort) via crafted BER data.
Affected Software
3 affected components
gnupg Libksba<=1.3.2
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Event History
Jun 13, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4353?
CVE-2016-4353 has a moderate severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2016-4353?
To fix CVE-2016-4353, upgrade Libksba to version 1.3.3 or later.
3
What systems are affected by CVE-2016-4353?
CVE-2016-4353 affects Libksba versions prior to 1.3.3 and certain versions of Ubuntu Linux 12.04 and 14.04.
4
What type of vulnerability is CVE-2016-4353?
CVE-2016-4353 is a denial of service vulnerability caused by improper handling of decoder stack overflows.
5
Can CVE-2016-4353 be exploited remotely?
Yes, CVE-2016-4353 can be exploited remotely through crafted BER data.