5
CVSSv2

CVE-2016-4356

Published: 13/06/2016 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The append_utf8_value function in the DN decoder (dn.c) in Libksba prior to 1.3.3 allows remote malicious users to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after invalid utf-8 encoded data.

Vulnerable Product Search on Vulmon Subscribe to Product

gnupg libksba

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

Vendor Advisories

Libksba could be made to crash or run programs if it decoded specially crafted data ...
The append_utf8_value function in the DN decoder (dnc) in Libksba before 133 allows remote attackers to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after invalid utf-8 encoded data ...