CVE-2016-9427
published 2016-12-12CVE-2016-9427: Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and possibly…
PriorityP344critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.14%
89.7th percentile
Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and possibly execute arbitrary code via huge allocation.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bdwgc_project | bdwgc | <= 7.4.4 | — |
| debian | debian_linux | — | — |
| debian | libgc | < libgc 1:7.6.4-0.3 (bookworm) | libgc 1:7.6.4-0.3 (bookworm) |
| debian | w3m | < w3m 0.5.3-30 (bookworm) | w3m 0.5.3-30 (bookworm) |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| tats | w3m | <= 0.5.3-30 | — |
| tats | w3m | >= 0 < 0.5.3-30 | 0.5.3-30 |
| tats | w3m | >= 0 < 0.5.3-30 | 0.5.3-30 |
| tats | w3m | >= 0 < 0.5.3-30 | 0.5.3-30 |
| tats | w3m | >= 0 < 0.5.3-30 | 0.5.3-30 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r3r3-3c87-427g: An issue was discovered in the Tatsuya Kinoshita w3m fork before 0
ghsa_unreviewed·2022-05-17·CVSS 9.8
CVE-2016-9426 [CRITICAL] CWE-190 GHSA-r3r3-3c87-427g: An issue was discovered in the Tatsuya Kinoshita w3m fork before 0
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Integer overflow vulnerability in the renderTable function in w3m allows remote attackers to cause a denial of service (OOM) and possibly execute arbitrary code due to bdwgc's bug (CVE-2016-9427) via a crafted HTML page.
GHSA
GHSA-mg78-4mqg-2c9m: Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and
ghsa_unreviewed·2022-05-13
CVE-2016-9427 [CRITICAL] CWE-119 GHSA-mg78-4mqg-2c9m: Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and
Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and possibly execute arbitrary code via huge allocation.
OSV
CVE-2016-9426: An issue was discovered in the Tatsuya Kinoshita w3m fork before 0
osv·2016-12-12·CVSS 8.8
CVE-2016-9426 [HIGH] CVE-2016-9426: An issue was discovered in the Tatsuya Kinoshita w3m fork before 0
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Integer overflow vulnerability in the renderTable function in w3m allows remote attackers to cause a denial of service (OOM) and possibly execute arbitrary code due to bdwgc's bug (CVE-2016-9427) via a crafted HTML page.
OSV
CVE-2016-9427: Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and
osv·2016-12-12·CVSS 9.8
CVE-2016-9427 [CRITICAL] CVE-2016-9427: Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and
Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and possibly execute arbitrary code via huge allocation.
Ubuntu
libgc vulnerability
vendor_ubuntu·2017-02-15
CVE-2016-9427 libgc vulnerability
Title: libgc vulnerability
Summary: Applications using libgc could be made to crash or run programs as
your login.
Kuang-che Wu discovered that multiple integer overflow vulnerabilities
existed in libgc. An attacker could use these to cause a denial of
service (application crash) or possibly execute arbitrary code.
Instructions: After a standard system update you need to restart applications using
libgc to make all the necessary changes.
Red Hat
gc: Integer overflow in GC_MALLOC_ATOMIC
vendor_redhat·2016-08-21·CVSS 9.8
CVE-2016-9427 [CRITICAL] CWE-190 gc: Integer overflow in GC_MALLOC_ATOMIC
gc: Integer overflow in GC_MALLOC_ATOMIC
Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and possibly execute arbitrary code via huge allocation.
Package: gc (Red Hat Enterprise Linux 6) - Will not fix
Package: gcc (Red Hat Enterprise Linux 6) - Will not fix
Package: gc (Red Hat Enterprise Linux 7) - Will not fix
Red Hat
w3m: Heap corruption due to integer overflow in renderTable()
vendor_redhat·2016-08-19·CVSS 8.8
CVE-2016-9426 [HIGH] CWE-190 w3m: Heap corruption due to integer overflow in renderTable()
w3m: Heap corruption due to integer overflow in renderTable()
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Integer overflow vulnerability in the renderTable function in w3m allows remote attackers to cause a denial of service (OOM) and possibly execute arbitrary code due to bdwgc's bug (CVE-2016-9427) via a crafted HTML page.
Package: w3m (Red Hat Enterprise Linux 5) - Will not fix
Package: w3m (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2016-9426: w3m - An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Integ...
vendor_debian·2016·CVSS 8.8
CVE-2016-9426 [HIGH] CVE-2016-9426: w3m - An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Integ...
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Integer overflow vulnerability in the renderTable function in w3m allows remote attackers to cause a denial of service (OOM) and possibly execute arbitrary code due to bdwgc's bug (CVE-2016-9427) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 0.5.3-30)
bullseye: resolved (fixed in 0.5.3-30)
forky: resolved (fixed in 0.5.3-30)
sid: resolved (fixed in 0.5.3-30)
trixie: resolved (fixed in 0.5.3-30)
Debian
CVE-2016-9427: libgc - Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to ca...
vendor_debian·2016·CVSS 9.8
CVE-2016-9427 [CRITICAL] CVE-2016-9427: libgc - Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to ca...
Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and possibly execute arbitrary code via huge allocation.
Scope: local
bookworm: resolved (fixed in 1:7.6.4-0.3)
bullseye: resolved (fixed in 1:7.6.4-0.3)
forky: resolved (fixed in 1:7.6.4-0.3)
sid: resolved (fixed in 1:7.6.4-0.3)
trixie: resolved (fixed in 1:7.6.4-0.3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9427 gc: Integer overflow in GC_MALLOC_ATOMIC [fedora-all]
bugzilla·2016-11-29·CVSS 9.8
CVE-2016-9427 [CRITICAL] CVE-2016-9427 gc: Integer overflow in GC_MALLOC_ATOMIC [fedora-all]
CVE-2016-9427 gc: Integer overflow in GC_MALLOC_ATOMIC [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Wh
Bugzilla
CVE-2016-9427 gc: Integer overflow in GC_MALLOC_ATOMIC
bugzilla·2016-11-29·CVSS 9.8
CVE-2016-9427 [CRITICAL] CVE-2016-9427 gc: Integer overflow in GC_MALLOC_ATOMIC
CVE-2016-9427 gc: Integer overflow in GC_MALLOC_ATOMIC
A heap corruption due to integer overflow will occur in gc while parsing maliciously crafted input.
Upstream bug:
https://github.com/ivmai/bdwgc/issues/135
Upstream fixes:
https://github.com/ivmai/bdwgc/commit/4e1a6f9d8f2a49403bbd00b8c8e5324048fb84d4
https://github.com/ivmai/bdwgc/commit/7292c02fac2066d39dd1bcc37d1a7054fd1e32ee
https://github.com/ivmai/bdwgc/commit/552ad0834672fed86ada6430150ef9ebdd3f54d7
References:
http://seclists.org/oss-sec/2016/q4/321
Discussion:
Created gc tracking bugs for this issue:
Affects: fedora-all [bug 1399675]
Affects: epel-5 [bug 1399676]
Bugzilla
CVE-2016-9427 gc: Integer overflow in GC_MALLOC_ATOMIC [epel-5]
bugzilla·2016-11-29·CVSS 9.8
CVE-2016-9427 [CRITICAL] CVE-2016-9427 gc: Integer overflow in GC_MALLOC_ATOMIC [epel-5]
CVE-2016-9427 gc: Integer overflow in GC_MALLOC_ATOMIC [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Discussion:
U
http://lists.opensuse.org/opensuse-updates/2016-12/msg00089.htmlhttp://lists.opensuse.org/opensuse-updates/2016-12/msg00115.htmlhttp://www.openwall.com/lists/oss-security/2016/11/18/3http://www.securityfocus.com/bid/94407https://github.com/ivmai/bdwgc/issues/135https://lists.debian.org/debian-lts-announce/2022/03/msg00039.htmlhttp://lists.opensuse.org/opensuse-updates/2016-12/msg00089.htmlhttp://lists.opensuse.org/opensuse-updates/2016-12/msg00115.htmlhttp://www.openwall.com/lists/oss-security/2016/11/18/3http://www.securityfocus.com/bid/94407https://github.com/ivmai/bdwgc/issues/135https://lists.debian.org/debian-lts-announce/2022/03/msg00039.html
2016-12-12
Published