← Back

CVE-2016-10253

nvd nist
Published: Mar 18, 2017Modified: May 13, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions using a malformed extpattern can indirectly specify an offset that is used as an array index. This ordinal permits arbitrary regions within the erts_alloc arena to be both read and written to.

Affected (67)

Products: Erlang: Erlang/otp
1 product
Erlang/otp
Configuration A
67 vulnerable
Vulnerable SoftwareAffected Versions
Erlang
Version 18.0.1
Version 18.0.2
Version 18.0.3
Version 18.0
Version 18.0 rc1
Version 18.0 rc2
Version 18.1.1
Version 18.1.2
Version 18.1.3
Version 18.1.4
Version 18.1.5
Version 18.1
Version 18.2.1
Version 18.2.2
Version 18.2.3
Version 18.2.4.1
Version 18.2.4
Version 18.2
Version 18.3.1
Version 18.3.2
Version 18.3.3
Version 18.3.4.1
Version 18.3.4.2
Version 18.3.4.3
Version 18.3.4.4
Version 18.3.4.5
Version 18.3.4
Version 18.3
Version 19.0.1
Version 19.0.2
Version 19.0.3
Version 19.0.4
Version 19.0.5
Version 19.0.6
Version 19.0.7
Version 19.0
Version 19.0 rc1
Version 19.0 rc2
Version 19.1.1
Version 19.1.2
Version 19.1.3
Version 19.1.4
Version 19.1.5
Version 19.1.6.1
Version 19.1.6
Version 19.1
Version 19.2.1
Version 19.2.2
Version 19.2.3.1
Version 19.2.3
Version 19.2
Version 19.3.1
Version 19.3.2
Version 19.3.3
Version 19.3.4
Version 19.3.5
Version 19.3.6.1
Version 19.3.6.2
Version 19.3.6.3
Version 19.3.6.4
Version 19.3.6.5
Version 19.3.6.6
Version 19.3.6.7
Version 19.3.6.8
Version 19.3.6.9
Version 19.3.6
Version 19.3

References (4)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.