CVE-2016-5434: Medium severity Pacman Project Pacman vulnerability
Published Jan 30, 2017
·Updated
libalpm, as used in pacman 5.0.1, allows remote attackers to cause a denial of service (infinite loop or out-of-bounds read) via a crafted signature file.
Affected Software
1 affected component
Pacman Project Pacman=5.0.1
Remediation
Event History
Jan 30, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Dec 12, 58332
Event
06:33 PM
Frequently Asked Questions
1
What is the severity of CVE-2016-5434?
CVE-2016-5434 is classified as a denial of service vulnerability.
2
How do I fix CVE-2016-5434?
To fix CVE-2016-5434, upgrade to a version of pacman that is not affected by this vulnerability.
3
What is the impact of CVE-2016-5434?
CVE-2016-5434 can lead to an infinite loop or out-of-bounds read, resulting in a denial of service.
4
Which software is affected by CVE-2016-5434?
CVE-2016-5434 specifically impacts the pacman version 5.0.1.
5
Can CVE-2016-5434 be exploited remotely?
Yes, CVE-2016-5434 can be exploited by remote attackers through a specially crafted signature file.