Lucene search

K
ubuntucveUbuntu.comUB:CVE-2016-6318
HistorySep 07, 2016 - 12:00 a.m.

CVE-2016-6318

2016-09-0700:00:00
ubuntu.com
ubuntu.com
6

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

Stack-based buffer overflow in the FascistGecosUser function in
lib/fascist.c in cracklib allows local users to cause a denial of service
(application crash) or gain privileges via a long GECOS field, involving
longbuffer.

Bugs

Notes

Author Note
tyhicks Ubuntu’s chfn limits the total GECOS field length to 84 characters which is well within cracklib2’s buffer size of 2048. libpam-cracklib is not part of the default install so PAM cracklib support is not enabled in the majority of Ubuntu installs Ubuntu’s /etc/login.defs only allows unprivileged users to set their room number, work phone, and home phone
OSVersionArchitecturePackageVersionFilename
ubuntu14.04noarchcracklib2< anyUNKNOWN
ubuntu16.04noarchcracklib2< anyUNKNOWN

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%