[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2016-9036 -- libmsgpuck-dev, tarantool

ID: oval:org.secpod.oval:def:1901166Date: (C)2019-03-04   (M)2023-12-20
Class: VULNERABILITYFamily: unix




An exploitable incorrect return value vulnerability exists in the mp_check function of Tarantool"s Msgpuck library 1.0.3. A specially crafted packet can cause the mp_check function to incorrectly return success when trying to check if decoding a map16 packet will read outside the bounds of a buffer, resulting in a denial of service vulnerability.

Platform:
Ubuntu 16.04
Product:
libmsgpuck-dev
tarantool
Reference:
CVE-2016-9036
CVE    1
CVE-2016-9036
CPE    3
cpe:/o:ubuntu:ubuntu_linux:16.04
cpe:/a:tarantool:libmsgpuck-dev
cpe:/a:tarantool:tarantool

© SecPod Technologies