Memory corruption in Gnu - CVE-2016-10713

 

Memory corruption in Gnu - CVE-2016-10713

Published: February 19, 2018


Vulnerability identifier: #VU10656
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-10713
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition on the target system.

The weakness exists due to out-of-bounds access within pch_write_line() in pch.c. A local attacker can supply a specially crafted input, trigger memory corruption and cause the system to crash.

Affected software

Gnu
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
SUSE Linux
Fedora
patch (Alpine package)
patch

How to mitigate CVE-2016-10713

Update to version 2.7.6-1.

patch (Alpine package) - update to 2.7.5-r3
patch - addressed in versions 2.7.6-3.fc26, 2.7.6-3.fc27

External References

Related Security Bulletins