PublicDateAtUSN: 2017-01-13 16:59:00 UTC Candidate: CVE-2016-2090 PublicDate: 2017-01-13 16:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2090 https://blog.fuzzing-project.org/36-Heap-buffer-overflow-in-fgetwln-function-of-libbsd.html https://ubuntu.com/security/notices/USN-4243-1 Description: Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow. Ubuntu-Description: Notes: mdeslaur> archive search doesn't seem to locate fgetwln usage Bugs: https://bugs.freedesktop.org/show_bug.cgi?id=93881 Priority: low Discovered-by: Hanno Böck Assigned-to: leosilva CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_libbsd: upstream: http://cgit.freedesktop.org/libbsd/commit/?id=c8f0723d2b4520bdd6b9eb7c3e7976de726d7ff7 upstream_libbsd: released (0.8.2-1) precise_libbsd: not-affected (code not present) precise/esm_libbsd: not-affected (code not present) trusty_libbsd: ignored (reached end-of-life) trusty/esm_libbsd: released (0.6.0-2ubuntu1+esm1) vivid_libbsd: ignored (reached end-of-life) vivid/stable-phone-overlay_libbsd: ignored (reached end-of-life) vivid/ubuntu-core_libbsd: ignored (reached end-of-life) wily_libbsd: ignored (reached end-of-life) xenial_libbsd: not-affected (0.8.2-1) esm-infra/xenial_libbsd: not-affected (0.8.2-1) yakkety_libbsd: not-affected (0.8.2-1) zesty_libbsd: not-affected (0.8.2-1) artful_libbsd: not-affected (0.8.2-1) bionic_libbsd: not-affected (0.8.2-1) cosmic_libbsd: not-affected (0.8.2-1) disco_libbsd: not-affected (0.8.2-1) eoan_libbsd: not-affected (0.8.2-1) devel_libbsd: not-affected (0.8.2-1)