CVE-2016-5011
published 2017-04-11CVE-2016-5011: The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a denial of service…
medium4.6CVSS 3.1
AVPACLPRNUINSUCNINAH
The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a denial of service (memory consumption) via a crafted MSDOS partition table with an extended partition boot record at zero offset.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | util-linux | < util-linux 2.28.1-1 (bookworm) | util-linux 2.28.1-1 (bookworm) |
| ibm | power_hardware_management_console | — | — |
| ibm | powerkvm | — | — |
| ibm | powerkvm | — | — |
| kernel | util-linux | <= 2.28 | — |
| kernel | util-linux | >= 0 < 2.28.1-1 | 2.28.1-1 |
| kernel | util-linux | >= 0 < 2.28.1-1 | 2.28.1-1 |
| kernel | util-linux | >= 0 < 2.28.1-1 | 2.28.1-1 |
| kernel | util-linux | >= 0 < 2.28.1-1 | 2.28.1-1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.14.6MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv4.6MEDIUM