ALPINE-CVE-2016-6318 PUBLISHED CVSS 7.800000190734863 HIGH

Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges via a long GECOS field, involving longbuffer.

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.19cracklib2.9.6-r0, 2.9.4-r0, 2.9.1-r0
Alpine:v3.21cracklib0, 2.8.13-r0, 2.8.13-r1
Alpine:v3.18cracklib0, 2.9.6-r0, 2.9.4-r0
Alpine:v3.22cracklib0, 0, 2.8.13-r0
Alpine:v3.13cracklib0, 2.9.6-r0, 2.9.4-r0
Alpine:v3.14cracklib0, 0, 2.8.13-r0
Alpine:v3.23cracklib2.9.6-r0, 0, 2.8.13-r0
Alpine:v3.17cracklib2.8.13-r1, 0, 2.9.6-r0
Alpine:v3.10cracklib0, 2.9.6-r0, 2.9.4-r0
Alpine:v3.15cracklib2.8.13-r0, 0, 2.9.6-r0
Alpine:v3.20cracklib2.8.13-r0, 0, 2.9.6-r0
Alpine:v3.16cracklib2.9.6-r0, 0, 2.8.13-r1
Alpine:v3.11cracklib2.8.13-r0, 2.8.13-r1, 2.8.16-r0
Alpine:v3.12cracklib2.8.16-r0, 2.8.13-r1, 2.9.6-r0

Timeline

References

Open in Interactive Console →