CVE-2016-4487: Use After Free
Published Feb 24, 2017
·Updated
Last updated 24 July 2024
Other sources
Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to "btypevec."
Affected Software
4 affected componentsFixes available
GNU Libiberty
debian/binutils
2.35.2-22.40-22.44-3
debian/ht
2.1.0+repack1-5
debian/libiberty
20210106-120230104-120250315-1
Remediation
Event History
Feb 24, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:59 PM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:19 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:14 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2016-4487?
CVE-2016-4487 is a use-after-free vulnerability in libiberty that allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary.
2
Which software is affected by CVE-2016-4487?
The affected software includes binutils, libiberty, valgrind, and gdb.
3
How can the use-after-free vulnerability in libiberty be exploited?
The vulnerability can be exploited by remote attackers using a crafted binary.
4
What is the severity of CVE-2016-4487?
The severity of CVE-2016-4487 is high as it can lead to a denial of service.
5
Is there a fix available for CVE-2016-4487?
Yes, the recommended fix is to update the affected software to the specified versions.