CVE-2016-4355 describes multiple integer overflow vulnerabilities in Libksba versions prior to 1.3.3, specifically within the ber-decoder.c component. These flaws, affecting products like Canonical and GnuPG's Libksba, allow remote attackers to trigger a denial of service (crash) through crafted BER data, leading to a buffer overflow. With a CVSSv3 score of 7.5 (HIGH), this vulnerability is remotely exploitable with low attack complexity and no user interaction or privileges required, resulting in a high impact on availability. The EPSS score is low, suggesting a low probability of exploitation in the wild. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.2CPE matchmatch criteria | cpe:2.3:a:gnupg:libksba:*:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.