CVE-2016-4579: Input Validation
Published Jun 13, 2016
·Updated
Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "returned length of the object from ksbaberparsetl."
Affected Software
6 affected components
gnupg Libksba<=1.3.3
openSUSE Leap=42.1
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Canonical Ubuntu Linux=16.04
Event History
Jun 13, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4579?
CVE-2016-4579 has been classified as a high severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2016-4579?
To fix CVE-2016-4579, upgrade libksba to version 1.3.4 or later.
3
Which versions of software are affected by CVE-2016-4579?
CVE-2016-4579 affects libksba versions before 1.3.4, as well as specific versions of Ubuntu and openSUSE.
4
What type of attack does CVE-2016-4579 exploit?
CVE-2016-4579 can be exploited by remote attackers to trigger an out-of-bounds read leading to a crash.
5
Is there a workaround for CVE-2016-4579?
There is no documented workaround for CVE-2016-4579; upgrading to a secure version is the recommended approach.