Overview
The BSD libc library is vulnerable to a classic buffer overflow.
Description
CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') - CVE-2016-6559 Improper bounds checking of the obuf variable in the link_ntoa() function in linkaddr.c may allow an attacker to read or write from memory. |
Impact
The full impact and severity depends on the method of exploit and how the library is used by applications. An attacker may be able to execute arbitrary code, but CERT/CC is currently unaware of a proof of concept. |
Solution
Apply an update |
Vendor Information (Learn More)
Vendor | Status | Date Notified | Date Updated |
---|---|---|---|
Apple | Affected | 10 Oct 2016 | 16 Nov 2016 |
FreeBSD Project | Affected | 21 Oct 2016 | 21 Nov 2016 |
DesktopBSD | Unknown | 26 Oct 2016 | 26 Oct 2016 |
DragonFly BSD Project | Unknown | 26 Oct 2016 | 26 Oct 2016 |
F5 Networks, Inc. | Unknown | 26 Oct 2016 | 26 Oct 2016 |
Hardened BSD | Unknown | 26 Oct 2016 | 26 Oct 2016 |
Juniper Networks | Unknown | 26 Oct 2016 | 26 Oct 2016 |
NetBSD | Unknown | 26 Oct 2016 | 26 Oct 2016 |
Nokia | Unknown | 26 Oct 2016 | 26 Oct 2016 |
OpenBSD | Unknown | 26 Oct 2016 | 26 Oct 2016 |
PC-BSD | Unknown | 16 Nov 2016 | 16 Nov 2016 |
QNX Software Systems Inc. | Unknown | 26 Oct 2016 | 26 Oct 2016 |
TrueOS | Unknown | 16 Nov 2016 | 16 Nov 2016 |
CVSS Metrics (Learn More)
Group | Score | Vector |
---|---|---|
Base | 9.3 | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Temporal | 9.3 | E:ND/RL:ND/RC:ND |
Environmental | 7.0 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
- https://github.com/freebsd/freebsd/blob/386ddae58459341ec567604707805814a2128a57/lib/libc/net/linkaddr.c#L132
- http://cwe.mitre.org/data/definitions/120.html
'취약점 정보2' 카테고리의 다른 글
Firefox 원격 코드 실행 취약점 보안 업데이트 권고 (0) | 2016.12.07 |
---|---|
V3 제품군(개인용/기업용) 12월 정기패치 관련 공지 (0) | 2016.12.07 |
삼성모바일 안드로이드 11월 정기 업데이트 안내 (0) | 2016.12.06 |
삼성 모바일 안드로이드 12월 정기 보안 업데이트 공지 (0) | 2016.12.06 |
phpMyAdmin에 여러 취약점 (0) | 2016.12.06 |