CVE-2016-4354
CVE-2016-4354
ber-decoder.c in Libksba before 1.3.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://git.gnupg.org/cgi-bin/gitweb.cgi?p=libksba.git%3Ba=commit%3Bh=aea7b6032865740478ca4b706850a5217f1c3887https://security.gentoo.org/glsa/201604-04http://www.openwall.com/lists/oss-security/2016/04/29/5http://www.openwall.com/lists/oss-security/2016/04/29/8http://www.ubuntu.com/usn/USN-2982-1