Candidate: CVE-2016-6254 PublicDate: 2016-08-19 21:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6254 Description: Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted network packet. Ubuntu-Description: It was discovered that collectd mishandled certain malformed packets. A remote attacker could use this vulnerablility to cause collectd to crash or possibly execuite arbitrary code. Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H [9.1 CRITICAL] Patches_collectd: upstream_collectd: released (5.5.2-1) precise_collectd: ignored (reached end-of-life) precise/esm_collectd: DNE (precise was needed) trusty_collectd: ignored (out of standard support) trusty/esm_collectd: needed vivid/stable-phone-overlay_collectd: DNE vivid/ubuntu-core_collectd: DNE wily_collectd: ignored (reached end-of-life) xenial_collectd: ignored (end of standard support, was needed) yakkety_collectd: ignored (reached end-of-life) zesty_collectd: ignored (reached end-of-life) artful_collectd: ignored (reached end-of-life) bionic_collectd: not-affected (5.7.2-2ubuntu1) cosmic_collectd: not-affected (5.7.2-2ubuntu1) disco_collectd: not-affected (5.7.2-2ubuntu1) eoan_collectd: not-affected (5.7.2-2ubuntu1) focal_collectd: not-affected (5.7.2-2ubuntu1) groovy_collectd: not-affected (5.7.2-2ubuntu1) hirsute_collectd: not-affected (5.7.2-2ubuntu1) impish_collectd: not-affected (5.7.2-2ubuntu1) devel_collectd: not-affected (5.7.2-2ubuntu1)