Rapid7 Vulnerability & Exploit Database

SUSE: CVE-2016-6354: SUSE Linux Security Advisory

Free InsightVM Trial No Credit Card Necessary
2024 Attack Intel Report Latest research by Rapid7 Labs
Back to Search

SUSE: CVE-2016-6354: SUSE Linux Security Advisory

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
09/21/2016
Created
07/25/2018
Added
09/21/2016
Modified
02/04/2022

Description

Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read.

Solution(s)

  • suse-upgrade-at
  • suse-upgrade-bogofilter
  • suse-upgrade-firefox-fontconfig
  • suse-upgrade-flex
  • suse-upgrade-flex-32bit
  • suse-upgrade-libbonobo
  • suse-upgrade-libbonobo-32bit
  • suse-upgrade-libbonobo-devel
  • suse-upgrade-libbonobo-doc
  • suse-upgrade-libbonobo-lang
  • suse-upgrade-libfreebl3
  • suse-upgrade-libfreebl3-32bit
  • suse-upgrade-libkde4
  • suse-upgrade-libkde4-32bit
  • suse-upgrade-libkdecore4
  • suse-upgrade-libkdecore4-32bit
  • suse-upgrade-libksuseinstall1
  • suse-upgrade-libksuseinstall1-32bit
  • suse-upgrade-libnetpbm-devel
  • suse-upgrade-libnetpbm11
  • suse-upgrade-libnetpbm11-32bit
  • suse-upgrade-libqtwebkit-devel
  • suse-upgrade-libqtwebkit4
  • suse-upgrade-libqtwebkit4-32bit
  • suse-upgrade-libwireshark8
  • suse-upgrade-libwireshark9
  • suse-upgrade-libwiretap6
  • suse-upgrade-libwiretap7
  • suse-upgrade-libwscodecs1
  • suse-upgrade-libwsutil7
  • suse-upgrade-libwsutil8
  • suse-upgrade-mdbtools
  • suse-upgrade-mozilla-nspr
  • suse-upgrade-mozilla-nspr-32bit
  • suse-upgrade-mozilla-nspr-devel
  • suse-upgrade-mozilla-nss
  • suse-upgrade-mozilla-nss-32bit
  • suse-upgrade-mozilla-nss-devel
  • suse-upgrade-mozilla-nss-tools
  • suse-upgrade-mozillafirefox
  • suse-upgrade-mozillafirefox-branding-sled
  • suse-upgrade-mozillafirefox-devel
  • suse-upgrade-mozillafirefox-translations
  • suse-upgrade-mozillafirefox-translations-common
  • suse-upgrade-mozillafirefox-translations-other
  • suse-upgrade-mozillathunderbird
  • suse-upgrade-mozillathunderbird-buildsymbols
  • suse-upgrade-mozillathunderbird-devel
  • suse-upgrade-mozillathunderbird-translations-common
  • suse-upgrade-mozillathunderbird-translations-other
  • suse-upgrade-netpbm
  • suse-upgrade-openslp
  • suse-upgrade-openslp-32bit
  • suse-upgrade-openslp-devel
  • suse-upgrade-openslp-server
  • suse-upgrade-perl-cyrus-imap
  • suse-upgrade-perl-cyrus-sieve-managesieve
  • suse-upgrade-sgmltool
  • suse-upgrade-wireshark
  • suse-upgrade-wireshark-devel
  • suse-upgrade-wireshark-gtk

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;