CVE-2016-8859
published 2017-02-13CVE-2016-8859: Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, which…
PriorityP345critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.36%
87.4th percentile
Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, which triggers an out-of-bounds write.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | musl | < musl 1.1.15-2 (bookworm) | musl 1.1.15-2 (bookworm) |
| debian | tre | < musl 1.1.15-2 (bookworm) | musl 1.1.15-2 (bookworm) |
| etalabs | musl | <= 1.1.15 | — |
| musl-libc | musl | >= 0 < 1.1.15-2 | 1.1.15-2 |
| musl-libc | musl | >= 0 < 1.1.15-2 | 1.1.15-2 |
| musl-libc | musl | >= 0 < 1.1.15-2 | 1.1.15-2 |
| musl-libc | musl | >= 0 < 1.1.15-2 | 1.1.15-2 |
| musl-libc | musl | >= 0 < 0.9.15-1ubuntu0.1~esm1 | 0.9.15-1ubuntu0.1~esm1 |
| musl-libc | musl | >= 0 < 1.1.9-1ubuntu0.1~esm2 | 1.1.9-1ubuntu0.1~esm2 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
musl vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 9.8
CVE-2018-1000001 [CRITICAL] musl vulnerabilities
Title: musl vulnerabilities
Summary: Several security issues were fixed in musl.
It was discovered that musl did not properly handle kernel syscalls. An
attacker could use this vulnerability to cause a denial of service (crash)
or possibly execute arbitrary code. (CVE-2018-1000001)
It was discovered that musl did not properly handle the parsing of DNS
response codes. A remote attacker could use this vulnerability to cause
resource consumption (infinite loop), denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 14.04 ESM.
(CVE-2014-3484)
It was discovered that musl did not properly handle the parsing of DNS
response codes. A remote attacker could use this vulnerability to cause
resource consumption (infinite loop), denial of service, or possibly
execut
Debian
CVE-2016-8859: musl - Multiple integer overflows in the TRE library and musl libc allow attackers to c...
vendor_debian·2016·CVSS 9.8
CVE-2016-8859 [CRITICAL] CVE-2016-8859: musl - Multiple integer overflows in the TRE library and musl libc allow attackers to c...
Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, which triggers an out-of-bounds write.
Scope: local
bookworm: resolved (fixed in 1.1.15-2)
bullseye: resolved (fixed in 1.1.15-2)
forky: resolved (fixed in 1.1.15-2)
sid: resolved (fixed in 1.1.15-2)
trixie: resolved (fixed in 1.1.15-2)
GHSA
GHSA-2r68-mjqv-c389: Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, w
ghsa_unreviewed·2022-05-13
CVE-2016-8859 [CRITICAL] CWE-190 GHSA-2r68-mjqv-c389: Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, w
Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, which triggers an out-of-bounds write.
OSV
musl vulnerabilities
osv·2021-03-15·CVSS 9.8
CVE-2018-1000001 [CRITICAL] musl vulnerabilities
musl vulnerabilities
It was discovered that musl did not properly handle kernel syscalls. An
attacker could use this vulnerability to cause a denial of service (crash)
or possibly execute arbitrary code. (CVE-2018-1000001)
It was discovered that musl did not properly handle the parsing of DNS
response codes. A remote attacker could use this vulnerability to cause
resource consumption (infinite loop), denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 14.04 ESM.
(CVE-2014-3484)
It was discovered that musl did not properly handle the parsing of DNS
response codes. A remote attacker could use this vulnerability to cause
resource consumption (infinite loop), denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 16.04 ESM.
OSV
CVE-2016-8859: Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, w
osv·2017-02-13·CVSS 9.8
CVE-2016-8859 [CRITICAL] CVE-2016-8859: Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, w
Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, which triggers an out-of-bounds write.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-8859 tre: Regex integer overflow in buffer size computations [fedora-all]
bugzilla·2016-10-20·CVSS 9.8
CVE-2016-8859 [CRITICAL] CVE-2016-8859 tre: Regex integer overflow in buffer size computations [fedora-all]
CVE-2016-8859 tre: Regex integer overflow in buffer size computations [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2016-8859 tre: Regex integer overflow in buffer size computations
bugzilla·2016-10-20·CVSS 9.8
CVE-2016-8859 [CRITICAL] CVE-2016-8859 tre: Regex integer overflow in buffer size computations
CVE-2016-8859 tre: Regex integer overflow in buffer size computations
Due to incorrect use of integer types and missing overflow checks in
the tre_tnfa_run_parallel function's buffer overflow logic, the TRE
regex implementation (both original version and the one used in musl
libc) are subject to integer overflows in buffer size computation.
If the caller passes to regcomp a regular expression whose internal
representation requires a large number of states and/or a large number
of tags, too little space will be allocated during regexec, resulting
in out-of-bound memory writes.
An attacker who controls the regular expression and/or the string
being searched can potentially exploit these writes to achieve
controlled heap corruption.
References:
http://seclists.org/oss-sec/2016/q4/183
D
Bugzilla
CVE-2016-8859 tre: Regex integer overflow in buffer size computations [epel-all]
bugzilla·2016-10-20·CVSS 9.8
CVE-2016-8859 [CRITICAL] CVE-2016-8859 tre: Regex integer overflow in buffer size computations [epel-all]
CVE-2016-8859 tre: Regex integer overflow in buffer size computations [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00041.htmlhttp://www.openwall.com/lists/oss-security/2016/10/19/1http://www.openwall.com/lists/oss-security/2016/10/19/10http://www.securityfocus.com/bid/93795https://security.gentoo.org/glsa/201701-11https://security.gentoo.org/glsa/202007-43http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00041.htmlhttp://www.openwall.com/lists/oss-security/2016/10/19/1http://www.openwall.com/lists/oss-security/2016/10/19/10http://www.securityfocus.com/bid/93795https://security.gentoo.org/glsa/201701-11https://security.gentoo.org/glsa/202007-43
2017-02-13
Published