CVE-2016-4355: Buffer Overflow
Published Jun 13, 2016
·Updated
Multiple integer overflows in ber-decoder.c in Libksba before 1.3.3 allow remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.
Affected Software
3 affected components
gnupg Libksba<=1.3.2
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Event History
Jun 13, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4355?
CVE-2016-4355 is rated as a high severity vulnerability due to the potential for remote denial of service attacks.
2
How do I fix CVE-2016-4355?
To fix CVE-2016-4355, update to Libksba version 1.3.3 or later.
3
What causes the CVE-2016-4355 vulnerability?
CVE-2016-4355 is caused by multiple integer overflows in the ber-decoder.c file in Libksba.
4
On which systems does CVE-2016-4355 affect software?
CVE-2016-4355 affects Libksba versions up to 1.3.2 and specific versions of Ubuntu Linux, including 12.04 and 14.04.
5
Could CVE-2016-4355 lead to data loss?
CVE-2016-4355 primarily leads to a denial of service, which may disrupt service but does not directly cause data loss.