First published: Fri Jan 27 2017(Updated: )
Integer signedness error in libc/string/arm/memset.S in uClibc and uClibc-ng before 1.0.16 allows context-dependent attackers to cause a denial of service (crash) via a negative length value to the memset function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Uclibc Uclibc | ||
Uclibc-ng Project Uclibc-ng | <1.0.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6264 has been classified as a moderate severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2016-6264, you should upgrade uClibc or uClibc-ng to version 1.0.16 or later.
CVE-2016-6264 is caused by an integer signedness error in the memset function when handling negative length values.
CVE-2016-6264 affects versions of uClibc and uClibc-ng before 1.0.16.
CVE-2016-6264 can be exploited by context-dependent attackers, potentially leading to a crash of the affected application.