7.5
CVSSv3

CVE-2016-4478

Published: 13/06/2016 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme prior to 7.2.7 allows remote malicious users to cause a denial of service via vectors related to XMLRPC response encoding.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 13.2

opensuse leap 42.1

atheme atheme

debian debian linux 8.0

Vendor Advisories

It was discovered that a buffer overflow in the XMLRPC response encoding code of the Atheme IRC services may result in denial of service For the stable distribution (jessie), this problem has been fixed in version 6011-2+deb8u1 For the testing distribution (stretch), this problem has been fixed in version 707-2 For the unstable distribution ...