PT-2017-8947 · Uclibc · Uclibc+1

Lucian Cojocar

·

Published

2017-01-27

·

Updated

2021-05-19

·

CVE-2016-6264

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions uClibc-ng versions prior to 1.0.16 uClibc versions prior to 1.0.16
Description The issue is caused by an integer signedness error in the libc/string/arm/memset.S file, which allows context-dependent attackers to cause a denial of service (crash) by providing a negative length value to the memset function.
Recommendations For uClibc-ng versions prior to 1.0.16, update to version 1.0.16 or later. For uClibc versions prior to 1.0.16, update to version 1.0.16 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2016-6264
DLA-561-1

Affected Products

Uclibc
Uclibc-Ng