CVE-2016-6354
published 2016-09-21CVE-2016-6354: Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or…
PriorityP351critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
8.77%
94.6th percentile
Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flex | >= 0 < 2.6.1-1 | 2.6.1-1 |
| adobe | flex | >= 0 < 2.6.1-1 | 2.6.1-1 |
| adobe | flex | >= 0 < 2.6.1-1 | 2.6.1-1 |
| adobe | flex | >= 0 < 2.6.1-1 | 2.6.1-1 |
| debian | debian_linux | — | — |
| debian | firefox | < firefox 52.0.1-1 (sid) | firefox 52.0.1-1 (sid) |
| debian | firefox-esr | < firefox 52.0.1-1 (sid) | firefox 52.0.1-1 (sid) |
| debian | flex | < flex 2.6.1-1 (bookworm) | flex 2.6.1-1 (bookworm) |
| mozilla | firefox | < 45.9.0 | 45.9.0 |
| mozilla | firefox | < 53.0 | 53.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 53 | 53 |
| mozilla | firefox_esr | >= unspecified < 45.9 | 45.9 |
| mozilla | firefox_esr | >= unspecified < 52.1 | 52.1 |
| mozilla | thunderbird | < 52.1.0 | 52.1.0 |
| mozilla | thunderbird | >= unspecified < 52.1 | 52.1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Potential Buffer overflow in flex-generated code (MFSA 2017-11, MFSA 2017-12)
vendor_redhat·2017-04-19·CVSS 9.8
CVE-2017-5469 [CRITICAL] Mozilla: Potential Buffer overflow in flex-generated code (MFSA 2017-11, MFSA 2017-12)
Mozilla: Potential Buffer overflow in flex-generated code (MFSA 2017-11, MFSA 2017-12)
Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Package: firefox (Red Hat Enterprise Linux 5) - Will not fix
Package: thunderbird (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2017-5469: firefox - Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 ...
vendor_debian·2017·CVSS 9.8
CVE-2017-5469 [CRITICAL] CVE-2017-5469: firefox - Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 ...
Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Scope: local
sid: resolved (fixed in 52.0.1-1)
Red Hat
flex: buffer overflow in generated code (yy_get_next_buffer)
vendor_redhat·2016-07-18·CVSS 9.8
CVE-2016-6354 [CRITICAL] CWE-122 flex: buffer overflow in generated code (yy_get_next_buffer)
flex: buffer overflow in generated code (yy_get_next_buffer)
Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read.
Package: flex (Red Hat Enterprise Linux 5) - Not affected
Package: flex (Red Hat Enterprise Linux 6) - Not affected
Package: bogofilter (Red Hat Enterprise Linux 7) - Will not fix
Package: flex (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-6354: flex - Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6...
vendor_debian·2016·CVSS 9.8
CVE-2016-6354 [CRITICAL] CVE-2016-6354: flex - Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6...
Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read.
Scope: local
bookworm: resolved (fixed in 2.6.1-1)
bullseye: resolved (fixed in 2.6.1-1)
forky: resolved (fixed in 2.6.1-1)
sid: resolved (fixed in 2.6.1-1)
trixie: resolved (fixed in 2.6.1-1)
GHSA
GHSA-4c6r-jqvh-f3hm: Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2
ghsa_unreviewed·2022-05-17
CVE-2016-6354 [CRITICAL] CWE-119 GHSA-4c6r-jqvh-f3hm: Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2
Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read.
GHSA
GHSA-gpr5-cvq3-j445: Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex
ghsa_unreviewed·2022-05-14·CVSS 9.8
CVE-2017-5469 [CRITICAL] CWE-119 GHSA-gpr5-cvq3-j445: Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex
Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
OSV
CVE-2017-5469: Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex
osv·2018-06-11·CVSS 9.8
CVE-2017-5469 [CRITICAL] CVE-2017-5469: Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex
Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
OSV
CVE-2016-6354: Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2
osv·2016-09-21·CVSS 9.8
CVE-2016-6354 [CRITICAL] CVE-2016-6354: Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2
Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5469 Mozilla: Potential Buffer overflow in flex-generated code (MFSA 2017-11, MFSA 2017-12)
bugzilla·2017-04-19·CVSS 9.8
CVE-2017-5469 [CRITICAL] CVE-2017-5469 Mozilla: Potential Buffer overflow in flex-generated code (MFSA 2017-11, MFSA 2017-12)
CVE-2017-5469 Mozilla: Potential Buffer overflow in flex-generated code (MFSA 2017-11, MFSA 2017-12)
Fixed potential buffer overflows in generated Firefox code due to [CVE-2016-6354](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6354) issue in Flex.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-11/#CVE-2017-5469
Acknowledgements:
Name: the Mozilla project
Upstream: Petr Cerny
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2017:1104 https://access.redhat.com/errata/RHSA-2017:1104
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:1106 https://access.redhat.com/errata/RHSA-2017:1106
---
This issue has been addressed in the fol
Bugzilla
flex: buffer overflow in generated code
bugzilla·2016-08-05·CVSS 9.8
CVE-2016-6354 [CRITICAL] flex: buffer overflow in generated code
flex: buffer overflow in generated code
Created attachment 8778238
mozilla-flex_buffer_overrun.patch
http://seclists.org/oss-sec/2016/q3/163
CVE-2016-6354
Some versions of The Fast Lexical Analyzer contain a bug which causes it to produce code potentially vulnerable to a buffer overrun.
While the fix should be made upstream (CMU Sphinx and ANGLE) in the first place, it might be a good idea to apply this hotfix for now.
Discussion:
making sure this is on milan's radar
---
Petr, do you know if this has been filed against ANGLE itself?
---
(In reply to Milan Sreckovic [:milan] from comment #2)
> Petr, do you know if this has been filed against ANGLE itself?
I have no idea, although it doesn't seem to be public in their issue racking system.
I have reported the issue to CMU Sphinx
Bugzilla
CVE-2016-6354 flex: buffer overflow in generated code (yy_get_next_buffer) [fedora-all]
bugzilla·2016-07-27·CVSS 9.8
CVE-2016-6354 [CRITICAL] CVE-2016-6354 flex: buffer overflow in generated code (yy_get_next_buffer) [fedora-all]
CVE-2016-6354 flex: buffer overflow in generated code (yy_get_next_buffer) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2016-6354 flex: buffer overflow in generated code (yy_get_next_buffer)
bugzilla·2016-07-27·CVSS 9.8
CVE-2016-6354 [CRITICAL] CVE-2016-6354 flex: buffer overflow in generated code (yy_get_next_buffer)
CVE-2016-6354 flex: buffer overflow in generated code (yy_get_next_buffer)
It was found that flex incorrectly resized the num_to_read variable in yy_get_next_buffer. The buffer is resized if this value is less or equal to zero.
With special crafted input it is possible, that the buffer is not resized if the input is larger than the default buffer size of 16k. This allows a heap buffer overflow.
It may be possible to exploit this remotely, depending on the application that is build using flex.
References:
http://seclists.org/oss-sec/2016/q3/97
Upstream patch:
https://github.com/westes/flex/commit/a5cbe929ac3255d371e698f62dc256afe7006466
Discussion:
Created flex tracking bugs for this issue:
Affects: fedora-all [bug 1360744]
---
flex-2.6.0-2.fc24 has been pushed to the Fedora 24
http://www.debian.org/security/2016/dsa-3653http://www.openwall.com/lists/oss-security/2016/07/18/8http://www.openwall.com/lists/oss-security/2016/07/26/12https://github.com/westes/flex/commit/a5cbe929ac3255d371e698f62dc256afe7006466https://security.gentoo.org/glsa/201701-31http://www.debian.org/security/2016/dsa-3653http://www.openwall.com/lists/oss-security/2016/07/18/8http://www.openwall.com/lists/oss-security/2016/07/26/12https://github.com/westes/flex/commit/a5cbe929ac3255d371e698f62dc256afe7006466https://security.gentoo.org/glsa/201701-31
2016-09-21
Published