ber-decoder.c in Libksba before 1.3.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2016-06-13T19:00:00

Updated: 2024-08-06T00:25:14.499Z

Reserved: 2016-04-29T00:00:00

Link: CVE-2016-4354

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2016-06-13T19:59:04.770

Modified: 2023-11-07T02:32:36.710

Link: CVE-2016-4354

cve-icon Redhat

Severity : Moderate

Publid Date: 2015-04-08T00:00:00Z

Links: CVE-2016-4354 - Bugzilla