5.9
CVSSv3

CVE-2016-4429

Published: 10/06/2016 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to cause a denial of service (crash) or possibly unspecified other impact via a flood of crafted ICMP and UDP packets.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse leap 42.1

opensuse opensuse 13.2

gnu glibc

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

canonical ubuntu linux 12.04

canonical ubuntu linux 18.04

Vendor Advisories

Debian Bug report logs - #840347 CVE-2016-4429 Package: src:libtirpc; Maintainer for src:libtirpc is Anibal Monsalve Salazar <anibal@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 10 Oct 2016 19:39:02 UTC Severity: grave Tags: security, upstream Found in version libtirpc/025-1 Fixed in ve ...
USN-3239-1 introduced a regression in the GNU C Library ...
Several security issues were fixed in the GNU C Library ...
USN-3239-1 introduced a regression in the GNU C Library ...
Several security issues were fixed in libtirpc ...
Several security issues were fixed in libtirpc ...

Recent Articles

Google prepares 47 Android bug fixes, ten of them rated Critical
The Register • Richard Chirgwin • 05 Dec 2017

Nexus and Pixel owners get their fixes on US Tuesday. The rest of us peasants have to wait

Google has teased 47 Android patches for Nexus and Pixel devices. Among the critical bugs in the Android Security Bulletin, five concern the media framework, one is system-level, four hit Qualcomm components. The worst, Google said, is one of the media framework bugs, not yet fully disclosed, but it “could enable a remote attacker using a specially crafted file to execute arbitrary code within the context of a privileged process”. Two of the media framework bugs only affect Android 6.0 (31 p...