CVE-2016-10253 PUBLISHED

An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions using a malformed extpattern can indirectly specify an offset that is used as an array index. This ordinal permits arbitrary regions within the erts_alloc arena to be both read and written to.

EPSS 0.51% · 66.3th percentile

Risk Scores

EPSS Score
0.51%
66.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSerlang0, 1:18.0-dfsg-1ubuntu1, 1:18.0-dfsg-1ubuntu2

Timeline

References

Open in Interactive Console →