CVE

Id
95856  
CVE No.
CVE-2016-9036  
Status
Candidate  
Description
An exploitable incorrect return value vulnerability exists in the mp_check function of Tarantool"s Msgpuck library 1.0.3. A specially crafted packet can cause the mp_check function to incorrectly return success when trying to check if decoding a map16 packet will read outside the bounds of a buffer, resulting in a denial of service vulnerability.  
Phase
Assigned (20161026)  
Votes
None (candidate not yet proposed)  
Comments