SB2016083101 - NULL pointer dereference in Debian Linux



SB2016083101 - NULL pointer dereference in Debian Linux

Published: August 31, 2016 Updated: August 9, 2020

Security Bulletin ID SB2016083101
CSH Severity
Medium
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) NULL pointer dereference (CVE-ID: CVE-2016-7118)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error. A remote attacker can trigger denial of service conditions via standard filesystem operations, as demonstrated by scp from an AUFS filesystem.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.