445
VMScore

CVE-2016-4354

Published: 13/06/2016 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

ber-decoder.c in Libksba prior to 1.3.3 uses an incorrect integer data type, which allows remote malicious users to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

gnupg libksba

Vendor Advisories

Libksba could be made to crash or run programs if it decoded specially crafted data ...
ber-decoderc in Libksba before 133 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow ...