Resource exhaustion - CVE-2016-6831

 

Resource exhaustion - CVE-2016-6831

Published: January 10, 2017 / Updated: August 4, 2020


Vulnerability identifier: #VU33497
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6831
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The "process-execute" and "process-spawn" procedures did not free memory correctly when the execve() call failed, resulting in a memory leak. This could be abused by an attacker to cause resource exhaustion or a denial of service. This affects all releases of CHICKEN up to and including 4.11 (it will be fixed in 4.12 and 5.0, which are not yet released).


Affected software

chicken (Alpine package)
chicken
Fedora

How to mitigate CVE-2016-6831

Install update from vendor's website.

chicken (Alpine package) - update to 4.11.1-r0
chicken - addressed in versions 4.11.0-3.el6, 4.11.0-3.el7, 4.11.0-3.fc24, 4.11.0-3.fc25, 4.12.0-2.el6, 4.12.0-2.el7

External References

Related Security Bulletins