Candidate: CVE-2015-1817 PublicDate: 2017-08-18 16:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1817 Description: Stack-based buffer overflow in the inet_pton function in network/inet_pton.c in musl libc 0.9.15 through 1.0.4, and 1.1.0 through 1.1.7 allows attackers to have unspecified impact via unknown vectors. Ubuntu-Description: It was discovered that musl did not properly handle parsing of ipv6 addresses. An attacker could use this vulnerability to cause a denial of service (crash) or possibly execute arbitrary code. Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=781497 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_musl: upstream_musl: released (1.1.9-1) lucid_musl: DNE precise_musl: DNE precise/esm_musl: DNE trusty_musl: ignored (reached end-of-life) trusty/esm_musl: DNE (trusty was needed) utopic_musl: ignored (reached end-of-life) vivid_musl: ignored (reached end-of-life) vivid/stable-phone-overlay_musl: DNE vivid/ubuntu-core_musl: DNE wily_musl: not-affected (1.1.9-1) xenial_musl: not-affected (1.1.9-1) yakkety_musl: not-affected (1.1.9-1) zesty_musl: not-affected (1.1.9-1) artful_musl: not-affected (1.1.9-1) bionic_musl: not-affected (1.1.9-1) cosmic_musl: not-affected (1.1.9-1) disco_musl: not-affected (1.1.9-1) devel_musl: not-affected (1.1.9-1)