SB2016050929 - Improper input validation in pcre (Alpine package)
Published: May 9, 2016
Security Bulletin ID
SB2016050929
Severity
High
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper input validation (CVE-ID: CVE-2016-1263)
The vulnerability allows a remote attacker to cause the target system to crash.The vulnerability exists due to state error in Juniper Junos. A remote unauthenticated attacker can cause a kernel crash by sending a specially crafted UDP packet destined to the target interface IP address on a 64-bit system.
32-bit systems are not affected.
Successful exploitation of this vulnerability may result in denial of service.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=c58cc10617a25816b6be491359d820a8ef08e240
- https://git.alpinelinux.org/aports/commit/?id=1e4709887b69db528ad1b8d34d303e1eb6f464dc
- https://git.alpinelinux.org/aports/commit/?id=ae07363ba5d06022ffa7d161ab322fae828b7600
- https://git.alpinelinux.org/aports/commit/?id=dc49e78d743a23b436e3b37a722f73b7aa01e0ea
- https://git.alpinelinux.org/aports/commit/?id=1cabd618771bbdcfb71da232ac9b9d5719e62ec3