CVE-2016-9427: Buffer Overflow
Published Dec 12, 2016
·Updated
Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and possibly execute arbitrary code via huge allocation.
Affected Software
5 affected components
Bdwgc Project Bdwgc<=7.4.4
Debian Debian Linux=9.0
openSUSE Leap=42.1
openSUSE Leap=42.2
openSUSE openSUSE=13.2
Remediation
Patch Available
Event History
Dec 12, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9427?
CVE-2016-9427 has a high severity as it can lead to denial of service and potential arbitrary code execution.
2
How do I fix CVE-2016-9427?
To fix CVE-2016-9427, update bdwgc to version 7.4.5 or later.
3
Which versions of bdwgc are affected by CVE-2016-9427?
CVE-2016-9427 affects bdwgc versions before 7.4.5.
4
What are the consequences of exploiting CVE-2016-9427?
Exploiting CVE-2016-9427 can result in a heap buffer overflow crash and could allow attackers to execute arbitrary code.
5
Which operating systems are impacted by CVE-2016-9427?
CVE-2016-9427 impacts various distributions including Debian 9.0 and openSUSE versions 13.2, 42.1, and 42.2.