Memory corruption in Gnu - CVE-2016-10713
Published: February 19, 2018
Vulnerability identifier: #VU10656
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-10713
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to cause DoS condition on the target system.
The weakness exists due to out-of-bounds access within pch_write_line() in pch.c. A local attacker can supply a specially crafted input, trigger memory corruption and cause the system to crash.
The weakness exists due to out-of-bounds access within pch_write_line() in pch.c. A local attacker can supply a specially crafted input, trigger memory corruption and cause the system to crash.
Affected software
Gnu
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
SUSE Linux
Fedora
patch (Alpine package)
patch
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
SUSE Linux
Fedora
patch (Alpine package)
patch
How to mitigate CVE-2016-10713
Update to version 2.7.6-1.
patch (Alpine package) - update to 2.7.5-r3
patch - addressed in versions 2.7.6-3.fc26, 2.7.6-3.fc27
patch - addressed in versions 2.7.6-3.fc26, 2.7.6-3.fc27