Resource exhaustion - CVE-2016-6831
Published: January 10, 2017 / Updated: August 4, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The "process-execute" and "process-spawn" procedures did not free memory correctly when the execve() call failed, resulting in a memory leak. This could be abused by an attacker to cause resource exhaustion or a denial of service. This affects all releases of CHICKEN up to and including 4.11 (it will be fixed in 4.12 and 5.0, which are not yet released).
Affected software
chicken
Fedora
How to mitigate CVE-2016-6831
chicken - addressed in versions 4.11.0-3.el6, 4.11.0-3.el7, 4.11.0-3.fc24, 4.11.0-3.fc25, 4.12.0-2.el6, 4.12.0-2.el7