CVE-2016-4973

HIGH

GNU libssp - Buffer Overflow via Missing Object Size Checking

Title source: llm
STIX 2.1

Description

Binaries compiled against targets that use the libssp library in GCC for stack smashing protection (SSP) might allow local users to perform buffer overflow attacks by leveraging lack of the Object Size Checking feature.

References (3)

Core 3
Core References
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1324759
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/92530
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/08/17/6

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 10.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (1)
gnu/libssp
Published Jun 07, 2017
Tracked Since Feb 18, 2026