SB2016122908 - Resource exhaustion in chicken (Alpine package)
Published: December 29, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource exhaustion (CVE-ID: CVE-2016-6831)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The "process-execute" and "process-spawn" procedures did not free memory correctly when the execve() call failed, resulting in a memory leak. This could be abused by an attacker to cause resource exhaustion or a denial of service. This affects all releases of CHICKEN up to and including 4.11 (it will be fixed in 4.12 and 5.0, which are not yet released).
Remediation
Install update from vendor's website.