Stack-based buffer overflow in cracklib - CVE-2016-6318
Published: May 25, 2020
cracklib
cracklib
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the FascistGecosUser() function in lib/fascist.c when processing a long GECOS field, involving longbuffer. A remote unauthenticated attacker can trigger a stack-based buffer overflow via an overly long password string and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.