CVE-2016-4356: Buffer Overflow
Published Jun 13, 2016
·Updated
The appendutf8value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after invalid utf-8 encoded data.
Affected Software
3 affected components
gnupg Libksba<=1.3.2
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Event History
Jun 13, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4356?
CVE-2016-4356 has a severity classification that indicates a denial of service vulnerability due to out-of-bounds read.
2
How do I fix CVE-2016-4356?
To fix CVE-2016-4356, upgrade to Libksba version 1.3.3 or later.
3
Which versions of Libksba are affected by CVE-2016-4356?
Libksba versions prior to 1.3.3 are affected by CVE-2016-4356.
4
What type of attack does CVE-2016-4356 enable?
CVE-2016-4356 enables attackers to perform a denial of service attack by causing an out-of-bounds read.
5
Is CVE-2016-4356 specific to certain operating systems?
Yes, CVE-2016-4356 impacts systems running affected versions of Libksba on Ubuntu 12.04 and 14.04.