CVE-2016-6354
Summary
| CVE | CVE-2016-6354 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-09-21 14:25:00 UTC |
| Updated | 2023-10-06 17:12:00 UTC |
| Description | Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| oss-security - CVE request: flex: Buffer overflow in generated code
(yy_get_next_buffer) |
MLIST |
www.openwall.com |
Release Notes, Third Party Advisory |
| Fixed incorrect integer type · westes/flex@a5cbe92 · GitHub |
CONFIRM |
github.com |
Patch |
| flex: Potential insecure code generation (GLSA 201701-31) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| oss-security - Re: CVE request: flex: Buffer overflow in generated code (yy_get_next_buffer) |
MLIST |
www.openwall.com |
Release Notes, Third Party Advisory |
| Debian -- Security Information -- DSA-3653-1 flex |
DEBIAN |
www.debian.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710287 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 201802-03)
- 710520 Gentoo Linux flex Potential insecure code generation Vulnerability (GLSA 201701-31)