[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3636-1 collectd -- collectd

ID: oval:org.secpod.oval:def:602575Date: (C)2016-08-09   (M)2023-12-20
Class: PATCHFamily: unix




Emilien Gaspar discovered that collectd, a statistics collection and monitoring daemon, incorrectly processed incoming network packets. This resulted in a heap overflow, allowing a remote attacker to either cause a DoS via application crash, or potentially execute arbitrary code. Additionally, security researchers at Columbia University and the University of Virginia discovered that collectd failed to verify a return value during initialization. This meant the daemon could sometimes be started without the desired, secure settings.

Platform:
Debian 8.x
Product:
collectd
Reference:
DSA-3636-1
CVE-2016-6254
CVE    1
CVE-2016-6254
CPE    2
cpe:/a:collectd:collectd
cpe:/o:debian:debian_linux:8.x

© SecPod Technologies