PublicDateAtUSN: 2016-12-11 Candidate: CVE-2016-9427 PublicDate: 2016-12-12 02:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9427 https://github.com/ivmai/bdwgc/issues/135 http://www.openwall.com/lists/oss-security/2016/11/18/3 https://ubuntu.com/security/notices/USN-3197-1 Description: Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and possibly execute arbitrary code via huge allocation. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Kuang-che Wu Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_libgc: upstream: https://github.com/ivmai/bdwgc/commit/0b6818708f7644db5c7bd0cc80e7adaa5a889257 (7.4 branch) upstream: https://github.com/ivmai/bdwgc/commit/1f3c938e5482e3770df2163ab03ed760fd12155a (7.4 branch) upstream: https://github.com/ivmai/bdwgc/commit/41a9ed4cc88c0ed92403e1bd720c68d26c632352 (7.4 branch) upstream: https://github.com/ivmai/bdwgc/commit/e273661227b4684265c09e04f75db81f7c5e697e (testcases) upstream: https://github.com/ivmai/bdwgc/commit/2ea6d85adc5fe07d7e9c5d35f2e5886857338681 (7.2 branch) upstream: https://github.com/ivmai/bdwgc/commit/949a7533d47e0ce0976e2d7aa3daa3bf9f31cabd (7.2 branch) upstream: https://github.com/ivmai/bdwgc/commit/a230ee8b21111b88749a97e6801048db1859a0fc (7.2 branch) upstream_libgc: needs-triage precise_libgc: released (1:7.1-8ubuntu0.12.04.3) trusty_libgc: released (1:7.2d-5ubuntu2.1) trusty/esm_libgc: released (1:7.2d-5ubuntu2.1) vivid/stable-phone-overlay_libgc: DNE vivid/ubuntu-core_libgc: DNE xenial_libgc: released (1:7.4.2-7.3ubuntu0.1) esm-infra/xenial_libgc: released (1:7.4.2-7.3ubuntu0.1) yakkety_libgc: released (1:7.4.2-8ubuntu0.1) devel_libgc: released (1:7.4.2-8ubuntu1)