CVE-2016-6082Use After Free in Corporation Bigfix Platform

CWE-416Use After Free3 documents3 sources
Severity
10.0CRITICALNVD
EPSS
7.4%
top 8.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 1
Latest updateMay 17

Description

IBM BigFix Platform could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free race condition. An attacker could exploit this vulnerability to execute arbitrary code on the system.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 3.9 | Impact: 6.0

Affected Packages2 packages

NVDibm/bigfix_platform4 versions+3
CVEListV5ibm_corporation/bigfix_platform4 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8jj8-g8wj-q299: IBM BigFix Platform could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free race condition2022-05-17
CVEList
CVE-2016-6082: IBM BigFix Platform could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free race condition2017-02-01
CVE-2016-6082 — Use After Free | cvebase