CVE-2016-6318
published 2016-09-07CVE-2016-6318: Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash)…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.75%
50.7th percentile
Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges via a long GECOS field, involving longbuffer.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cracklib_project | cracklib | >= 2.9.0 < 2.9.6 | 2.9.6 |
| debian | cracklib2 | < cracklib2 2.9.2-2 (bookworm) | cracklib2 2.9.2-2 (bookworm) |
| debian | debian_linux | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f7mv-c94v-v96r: Stack-based buffer overflow in the FascistGecosUser function in lib/fascist
ghsa_unreviewed·2022-05-13
CVE-2016-6318 [HIGH] CWE-787 GHSA-f7mv-c94v-v96r: Stack-based buffer overflow in the FascistGecosUser function in lib/fascist
Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges via a long GECOS field, involving longbuffer.
OSV
CVE-2016-6318: Stack-based buffer overflow in the FascistGecosUser function in lib/fascist
osv·2016-09-07·CVSS 7.8
CVE-2016-6318 [HIGH] CVE-2016-6318: Stack-based buffer overflow in the FascistGecosUser function in lib/fascist
Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges via a long GECOS field, involving longbuffer.
Red Hat
cracklib: Stack-based buffer overflow when parsing large GECOS field
vendor_redhat·2016-08-16·CVSS 7.8
CVE-2016-6318 [HIGH] cracklib: Stack-based buffer overflow when parsing large GECOS field
cracklib: Stack-based buffer overflow when parsing large GECOS field
Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges via a long GECOS field, involving longbuffer.
Package: cracklib (Red Hat Enterprise Linux 5) - Will not fix
Package: cracklib (Red Hat Enterprise Linux 6) - Will not fix
Package: cracklib (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-6318: cracklib2 - Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in...
vendor_debian·2016·CVSS 7.8
CVE-2016-6318 [HIGH] CVE-2016-6318: cracklib2 - Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in...
Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges via a long GECOS field, involving longbuffer.
Scope: local
bookworm: resolved (fixed in 2.9.2-2)
bullseye: resolved (fixed in 2.9.2-2)
forky: resolved (fixed in 2.9.2-2)
sid: resolved (fixed in 2.9.2-2)
trixie: resolved (fixed in 2.9.2-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6318 cracklib: Stack-based buffer overflow when parsing large GECOS field [fedora-all]
bugzilla·2016-08-16·CVSS 7.8
CVE-2016-6318 [HIGH] CVE-2016-6318 cracklib: Stack-based buffer overflow when parsing large GECOS field [fedora-all]
CVE-2016-6318 cracklib: Stack-based buffer overflow when parsing large GECOS field [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2016-6318 cracklib: Stack-based buffer overflow when parsing large GECOS field
bugzilla·2016-08-08·CVSS 7.8
CVE-2016-6318 [HIGH] CVE-2016-6318 cracklib: Stack-based buffer overflow when parsing large GECOS field
CVE-2016-6318 cracklib: Stack-based buffer overflow when parsing large GECOS field
A stack-based overflow was found in the way cracklib, a library used to stop users from choosing easy to guess passwords, handled large GECOS field in the /etc/passwd file. When an application compiled against the cracklib libary, such as "passwd" is used to parse the GECOS field, it could cause the application to crash or execute arbitary code with the permissions of the user running such an application.
Discussion:
Created attachment 1188599
Proposed patch
---
The buffer overflow problem is present in RHEL-5 and RHEL-6 too however there the overflow will be in static data not on stack I believe so it might not crash there as easily.
---
The move of some buffers from static data to stack is not upstr
http://lists.opensuse.org/opensuse-updates/2016-08/msg00122.htmlhttp://www.openwall.com/lists/oss-security/2016/08/16/2http://www.securityfocus.com/bid/92478https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/05/msg00023.htmlhttps://security.gentoo.org/glsa/201612-25http://lists.opensuse.org/opensuse-updates/2016-08/msg00122.htmlhttp://www.openwall.com/lists/oss-security/2016/08/16/2http://www.securityfocus.com/bid/92478https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/05/msg00023.htmlhttps://security.gentoo.org/glsa/201612-25
2016-09-07
Published