CVE-2016-10253
Ubuntu Security Notice USN-3571-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions using a malformed extpattern can indirectly specify an offset that is used as an array index. This ordinal permits arbitrary regions within the erts_alloc arena to be both read and written to.
Se ha descubierto un problema en Erlang/OTP 18.x. La generación de expresiones regulares compiladas en Erlang es vulnerable a un desbordamiento de memoria dinámica. Las expresiones regulares que utilizan un extpattern mal formado pueden especificar indirectamente un desplazamiento que es utilizado como un índice del array. Este ordinal permite retiones arbitrarias dentro de la pista erts_alloc tanto para ser leído y escrito.
It was discovered that the Erlang FTP module incorrectly handled certain CRLF sequences. A remote attacker could possibly use this issue to inject arbitrary FTP commands. This issue only affected Ubuntu 14.04 LTS. It was discovered that Erlang incorrectly checked CBC padding bytes. A remote attacker could possibly use this issue to perform a padding oracle attack and decrypt traffic. This issue only affected Ubuntu 14.04 LTS. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-03-18 CVE Reserved
- 2017-03-18 CVE Published
- 2024-08-06 CVE Updated
- 2025-07-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/erlang/otp/pull/1108 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://usn.ubuntu.com/3571-1 | 2018-07-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.0 Search vendor "Erlang" for product "Erlang\/otp" and version "18.0" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.0 Search vendor "Erlang" for product "Erlang\/otp" and version "18.0" | rc1 |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.0 Search vendor "Erlang" for product "Erlang\/otp" and version "18.0" | rc2 |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.0.1 Search vendor "Erlang" for product "Erlang\/otp" and version "18.0.1" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.0.2 Search vendor "Erlang" for product "Erlang\/otp" and version "18.0.2" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.0.3 Search vendor "Erlang" for product "Erlang\/otp" and version "18.0.3" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.1 Search vendor "Erlang" for product "Erlang\/otp" and version "18.1" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.1.1 Search vendor "Erlang" for product "Erlang\/otp" and version "18.1.1" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.1.2 Search vendor "Erlang" for product "Erlang\/otp" and version "18.1.2" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.1.3 Search vendor "Erlang" for product "Erlang\/otp" and version "18.1.3" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.1.4 Search vendor "Erlang" for product "Erlang\/otp" and version "18.1.4" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.1.5 Search vendor "Erlang" for product "Erlang\/otp" and version "18.1.5" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.2 Search vendor "Erlang" for product "Erlang\/otp" and version "18.2" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.2.1 Search vendor "Erlang" for product "Erlang\/otp" and version "18.2.1" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.2.2 Search vendor "Erlang" for product "Erlang\/otp" and version "18.2.2" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.2.3 Search vendor "Erlang" for product "Erlang\/otp" and version "18.2.3" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.2.4 Search vendor "Erlang" for product "Erlang\/otp" and version "18.2.4" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.2.4.1 Search vendor "Erlang" for product "Erlang\/otp" and version "18.2.4.1" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.3 Search vendor "Erlang" for product "Erlang\/otp" and version "18.3" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.3.1 Search vendor "Erlang" for product "Erlang\/otp" and version "18.3.1" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.3.2 Search vendor "Erlang" for product "Erlang\/otp" and version "18.3.2" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.3.3 Search vendor "Erlang" for product "Erlang\/otp" and version "18.3.3" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.3.4 Search vendor "Erlang" for product "Erlang\/otp" and version "18.3.4" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.3.4.1 Search vendor "Erlang" for product "Erlang\/otp" and version "18.3.4.1" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.3.4.2 Search vendor "Erlang" for product "Erlang\/otp" and version "18.3.4.2" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.3.4.3 Search vendor "Erlang" for product "Erlang\/otp" and version "18.3.4.3" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.3.4.4 Search vendor "Erlang" for product "Erlang\/otp" and version "18.3.4.4" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 18.3.4.5 Search vendor "Erlang" for product "Erlang\/otp" and version "18.3.4.5" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.0 Search vendor "Erlang" for product "Erlang\/otp" and version "19.0" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.0 Search vendor "Erlang" for product "Erlang\/otp" and version "19.0" | rc1 |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.0 Search vendor "Erlang" for product "Erlang\/otp" and version "19.0" | rc2 |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.0.1 Search vendor "Erlang" for product "Erlang\/otp" and version "19.0.1" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.0.2 Search vendor "Erlang" for product "Erlang\/otp" and version "19.0.2" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.0.3 Search vendor "Erlang" for product "Erlang\/otp" and version "19.0.3" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.0.4 Search vendor "Erlang" for product "Erlang\/otp" and version "19.0.4" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.0.5 Search vendor "Erlang" for product "Erlang\/otp" and version "19.0.5" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.0.6 Search vendor "Erlang" for product "Erlang\/otp" and version "19.0.6" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.0.7 Search vendor "Erlang" for product "Erlang\/otp" and version "19.0.7" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.1 Search vendor "Erlang" for product "Erlang\/otp" and version "19.1" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.1.1 Search vendor "Erlang" for product "Erlang\/otp" and version "19.1.1" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.1.2 Search vendor "Erlang" for product "Erlang\/otp" and version "19.1.2" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.1.3 Search vendor "Erlang" for product "Erlang\/otp" and version "19.1.3" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.1.4 Search vendor "Erlang" for product "Erlang\/otp" and version "19.1.4" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.1.5 Search vendor "Erlang" for product "Erlang\/otp" and version "19.1.5" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.1.6 Search vendor "Erlang" for product "Erlang\/otp" and version "19.1.6" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.1.6.1 Search vendor "Erlang" for product "Erlang\/otp" and version "19.1.6.1" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.2 Search vendor "Erlang" for product "Erlang\/otp" and version "19.2" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.2.1 Search vendor "Erlang" for product "Erlang\/otp" and version "19.2.1" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.2.2 Search vendor "Erlang" for product "Erlang\/otp" and version "19.2.2" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.2.3 Search vendor "Erlang" for product "Erlang\/otp" and version "19.2.3" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.2.3.1 Search vendor "Erlang" for product "Erlang\/otp" and version "19.2.3.1" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.3 Search vendor "Erlang" for product "Erlang\/otp" and version "19.3" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.3.1 Search vendor "Erlang" for product "Erlang\/otp" and version "19.3.1" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.3.2 Search vendor "Erlang" for product "Erlang\/otp" and version "19.3.2" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.3.3 Search vendor "Erlang" for product "Erlang\/otp" and version "19.3.3" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.3.4 Search vendor "Erlang" for product "Erlang\/otp" and version "19.3.4" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.3.5 Search vendor "Erlang" for product "Erlang\/otp" and version "19.3.5" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.3.6 Search vendor "Erlang" for product "Erlang\/otp" and version "19.3.6" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.3.6.1 Search vendor "Erlang" for product "Erlang\/otp" and version "19.3.6.1" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.3.6.2 Search vendor "Erlang" for product "Erlang\/otp" and version "19.3.6.2" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.3.6.3 Search vendor "Erlang" for product "Erlang\/otp" and version "19.3.6.3" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.3.6.4 Search vendor "Erlang" for product "Erlang\/otp" and version "19.3.6.4" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.3.6.5 Search vendor "Erlang" for product "Erlang\/otp" and version "19.3.6.5" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.3.6.6 Search vendor "Erlang" for product "Erlang\/otp" and version "19.3.6.6" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.3.6.7 Search vendor "Erlang" for product "Erlang\/otp" and version "19.3.6.7" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.3.6.8 Search vendor "Erlang" for product "Erlang\/otp" and version "19.3.6.8" | - |
Affected
| ||||||
Erlang Search vendor "Erlang" | Erlang\/otp Search vendor "Erlang" for product "Erlang\/otp" | 19.3.6.9 Search vendor "Erlang" for product "Erlang\/otp" and version "19.3.6.9" | - |
Affected
|