CVE-2016-6264: High severity uClibc uClibc vulnerability
Published Jan 27, 2017
·Updated
Integer signedness error in libc/string/arm/memset.S in uClibc and uClibc-ng before 1.0.16 allows context-dependent attackers to cause a denial of service (crash) via a negative length value to the memset function.
Affected Software
2 affected components
uClibc uClibc
Uclibc-ng Project Uclibc-ng<1.0.16
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jan 27, 2017
CVE Published
via MITRE·10:01 PM
Data Sourced
via MITRE·10:01 PM
Description
Data Sourced
via NVD·10:59 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-6264?
CVE-2016-6264 has been classified as a moderate severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2016-6264?
To fix CVE-2016-6264, you should upgrade uClibc or uClibc-ng to version 1.0.16 or later.
3
What causes CVE-2016-6264?
CVE-2016-6264 is caused by an integer signedness error in the memset function when handling negative length values.
4
Which versions are affected by CVE-2016-6264?
CVE-2016-6264 affects versions of uClibc and uClibc-ng before 1.0.16.
5
Can CVE-2016-6264 be exploited remotely?
CVE-2016-6264 can be exploited by context-dependent attackers, potentially leading to a crash of the affected application.