CVE Vulnerabilities

CVE-2016-5011

Published: Apr 11, 2017 | Modified: Sep 11, 2020
CVSS 3.x
4.6
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.9 MEDIUM
AV:L/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
4.9 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:C
RedHat/V3
4.6 LOW
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
LOW

The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a denial of service (memory consumption) via a crafted MSDOS partition table with an extended partition boot record at zero offset.

Affected Software

Name Vendor Start Version End Version
Util-linux Kernel * 2.28 (including)
Red Hat Enterprise Linux 7 RedHat util-linux-0:2.23.2-33.el7 *
Util-linux Ubuntu artful *
Util-linux Ubuntu esm-infra-legacy/trusty *
Util-linux Ubuntu esm-infra/xenial *
Util-linux Ubuntu precise *
Util-linux Ubuntu precise/esm *
Util-linux Ubuntu trusty *
Util-linux Ubuntu trusty/esm *
Util-linux Ubuntu upstream *
Util-linux Ubuntu vivid/stable-phone-overlay *
Util-linux Ubuntu vivid/ubuntu-core *
Util-linux Ubuntu wily *
Util-linux Ubuntu xenial *
Util-linux Ubuntu yakkety *
Util-linux Ubuntu zesty *

References