Denial of service in Cisco Email Security Appliance - CVE-2016-6358

 

Denial of service in Cisco Email Security Appliance - CVE-2016-6358

Published: October 27, 2016 / Updated: April 5, 2018


Vulnerability identifier: #VU1087
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6358
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated user to cause DoS conditions on the target system.
The weakness is due to input validation flaw. By connecting to the FTP service and sending a specially crafted parameters, a remote attacker can trigger the target FTP service to crash.
Successful exploitation of the vulnerability results in denial of service on the vulnerable system.

Affected software

Cisco Email Security Appliance
SUSE Linux Enterprise Micro
libcairo2
libcairo-gobject2
libcairo-gobject2-debuginfo
cairo-debugsource
libcairo2-debuginfo

How to mitigate CVE-2016-6358

Update to version 9.1.1-038.

libcairo2 - update to 1.16.0-150400.11.3.1
libcairo-gobject2 - update to 1.16.0-150400.11.3.1
libcairo-gobject2-debuginfo - update to 1.16.0-150400.11.3.1
cairo-debugsource - update to 1.16.0-150400.11.3.1
libcairo2-debuginfo - update to 1.16.0-150400.11.3.1

External References

Related Security Bulletins