CVE-2016-10722
Last modified
CVE-2016-10722 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. partclone.fat in Partclone before 0.2.88 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the FAT superblock, related to the mark_reserved_sectors function. An attacker may be able to execute arbitrary code in the context of the user running the affected application.. EPSS estimates a 2.69% chance of exploitation in the next 30 days.
Description
partclone.fat in Partclone before 0.2.88 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the FAT superblock, related to the mark_reserved_sectors function. An attacker may be able to execute arbitrary code in the context of the user running the affected application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Partclone Project | Partclone | < 0.2.88 |
References
- https://david.gnedt.at/blog/2016/11/14/advisory-partclone-fat-bitmap-heap-overflow/Exploit, Third Party Advisory
- https://github.com/Thomas-Tsai/partclone/issues/71Issue Tracking, Third Party Advisory
- https://david.gnedt.at/blog/2016/11/14/advisory-partclone-fat-bitmap-heap-overflow/Exploit, Third Party Advisory
- https://github.com/Thomas-Tsai/partclone/issues/71Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-10722?
How severe is CVE-2016-10722?
How do I fix CVE-2016-10722?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-10716The Mail.ru Calendar plugin before 2.5.0.61 for Atlassian Ji…
- CVE-2016-10717A vulnerability in the encryption and permission implementat…
- CVE-2016-10718Brave Browser before 0.13.0 allows a tab to close itself eve…
- CVE-2016-10719TP-Link Archer CR-700 1.0.6 devices have an XSS vulnerabilit…
- CVE-2016-1072Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat…
- CVE-2016-10721partclone.restore in Partclone 0.2.87 is prone to a heap-bas…
- CVE-2016-10723An issue was discovered in the Linux kernel through 4.17.2. …
- CVE-2016-10724Bitcoin Core before v0.13.0 allows denial of service (memory…
- CVE-2016-10725In Bitcoin Core before v0.13.0, a non-final alert is able to…
- CVE-2016-10726The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and …
- CVE-2016-10727camel/providers/imapx/camel-imapx-server.c in the IMAPx comp…
- CVE-2016-10728An issue was discovered in Suricata before 3.1.2. If an ICMP…
Are you affected by CVE-2016-10722?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
