Do your applications use this vulnerable package?
Test your applications
Overview
The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a denial of service (memory consumption) via a crafted MSDOS partition table with an extended partition boot record at zero offset.
References
CVSS Score
4.6
medium severity
-
Attack VectorPhysical
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2016-5011
- Snyk ID
- SNYK-DEBIAN8-UTILLINUX-285812
- Disclosed
- 11 Apr, 2017
- Published
- 11 Apr, 2017