CVE-2016-6254: Buffer Overflow
Published Aug 19, 2016
·Updated
Heap-based buffer overflow in the parsepacket function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted network packet.
Affected Software
5 affected components
Debian Debian Linux=8.0
collectd collectd>=5.4.0<5.4.3
collectd collectd>=5.5.0<5.5.2
Fedoraproject Fedora=23
Fedoraproject Fedora=24
Remediation
Event History
Aug 19, 2016
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6254?
CVE-2016-6254 has a high severity rating due to the potential for denial of service or arbitrary code execution.
2
How do I fix CVE-2016-6254?
To fix CVE-2016-6254, upgrade to Collectd version 5.4.3 or later, or 5.5.2 or later.
3
Which software versions are affected by CVE-2016-6254?
CVE-2016-6254 affects Collectd versions prior to 5.4.3 and 5.5.2, as well as specific Debian and Fedora releases.
4
Can CVE-2016-6254 be exploited remotely?
Yes, CVE-2016-6254 can be exploited remotely through crafted network packets.
5
What are the potential impacts of CVE-2016-6254?
The potential impacts of CVE-2016-6254 include crashing the daemon and possibly executing arbitrary code.