CVE-2016-4354: Buffer Overflow
Published Jun 13, 2016
·Updated
ber-decoder.c in Libksba before 1.3.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.
Affected Software
3 affected components
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
gnupg Libksba<=1.3.2
Event History
Jun 13, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4354?
CVE-2016-4354 is classified as a high severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2016-4354?
To fix CVE-2016-4354, upgrade to Libksba version 1.3.3 or later.
3
What software is affected by CVE-2016-4354?
CVE-2016-4354 affects Libksba versions up to and including 1.3.2, and also impacts Ubuntu Linux versions 12.04 and 14.04.
4
Can CVE-2016-4354 be exploited remotely?
Yes, CVE-2016-4354 can be exploited by remote attackers using crafted BER data.
5
What is the impact of CVE-2016-4354?
The impact of CVE-2016-4354 is a denial of service condition that can lead to application crashes.