CVE-2016-4912: Null Pointer Dereference
A null pointer dereference vulnerability was found in function xrealloc() in xlspxmalloc.c in OpenSLP. A remote attacker could potentially crash the server when large number of packets are sent.
Vulnerable code:
void xrealloc(const char file, int line, void ptr, sizet size) { xallocationt x;
if (!ptr) return xmalloc(file, line, size);
if (!size) { xfree(file, line, ptr); return 0; }
x = xmallocfind(ptr); if (x != 0) { void newptr = ptr; if (x->size != size) { newptr = xmalloc(file, line, size); // return 0 if failed from xmalloc memcpy(newptr, ptr, x->size); // it'll cased a null pointer reference xfree(file, line, x); } return newptr; }
if (Gxmallocfh) fprintf(Gxmallocfh, " xrealloc called on " "non-xmalloc'd memory \n");
return 0; }
Other sources
The xrealloc function in xlspxmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4912?
CVE-2016-4912 has a medium severity rating due to its potential to cause a denial of service.
How do I fix CVE-2016-4912?
To fix CVE-2016-4912, you should upgrade to a patched version of OpenSLP that addresses this vulnerability.
Which versions of OpenSLP are affected by CVE-2016-4912?
CVE-2016-4912 affects OpenSLP version 2.0.0.
Can CVE-2016-4912 be exploited remotely?
Yes, CVE-2016-4912 can be exploited remotely by sending a large number of packets.
What type of attack can be executed using CVE-2016-4912?
An attacker can exploit CVE-2016-4912 to cause a null pointer dereference, potentially crashing the server.