CVE-2016-4472
🟠 Łataj w tym tygodniu
Usunięcie ochrony przed przepełnieniem bufora w Expat umożliwia zdalne wywołanie awarii lub wykonanie kodu.
CVSS
8.1
EPSS
11.9%
Exploit
none
Vendor
python
Opis źródłowy (NVD)
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716.
dos
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 11.9% |
| Opublikowano (NVD) | 2016-06-30 17:59:04 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 21:17:05 UTC |
Referencje
- http://www.securityfocus.com/bid/91528 ([email protected]) [Third Party Advisory, VDB Entry]
- http://www.ubuntu.com/usn/USN-3013-1 ([email protected]) [Third Party Advisory]
- https://bugzilla.redhat.com/show_bug.cgi?id=1344251 ([email protected]) [Issue Tracking, Patch, Third Party Advisory]
- https://kc.mcafee.com/corporate/index?page=content&id=SB10365 ([email protected]) [Third Party Advisory]
- https://security.gentoo.org/glsa/201701-21 ([email protected]) [Third Party Advisory]
- https://sourceforge.net/p/expat/code_git/ci/f0bec73b018caa07d3e75ec8dd967f3785d71bde ([email protected]) [Patch, Third Party Advisory]
- https://www.tenable.com/security/tns-2016-20 ([email protected]) [Third Party Advisory]