Heap-based buffer overflow in Debian Linux and Fedora - CVE-2016-6254
Published: August 20, 2016 / Updated: August 4, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2. A remote attacker can use a crafted network packet. to trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Fedora
Amazon Linux AMI
collectd (Alpine package)
collectd
How to mitigate CVE-2016-6254
collectd - addressed in versions 4.10.9-2.el5, 4.10.9-2.el6, 4.10.9-3.el5, 4.10.9-3.el6, 5.5.2-1.el7, 5.5.2-1.fc23, 5.5.2-1.fc24
External References
- http://collectd.org/news.shtml
- http://www.debian.org/security/2016/dsa-3636
- https://github.com/collectd/collectd/commit/b589096f907052b3a4da2b9ccc9b0e2e888dfc18
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CM4W5SJ4OTBGINGIN4NJLXCUZAZANO6J/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UIZ5UXDOB7BA5NGE2F2I2BL4K6763DHW/
Related Security Bulletins
- Heap-based buffer overflow in Debian Linux
- Heap-based buffer overflow in collectd (Alpine package)
- Amazon Linux AMI update for collectd
- Fedora 24 update for collectd
- Fedora 23 update for collectd
- Fedora EPEL 7 update for collectd
- Fedora EPEL 5 update for collectd
- Fedora EPEL 6 update for collectd
- Fedora EPEL 5 update for collectd
- Fedora EPEL 6 update for collectd