CVE-2016-6830
Last modified
CVE-2016-6830 is a vulnerability of currently unknown severity. The "process-execute" and "process-spawn" procedures in CHICKEN Scheme used fixed-size buffers for holding the arguments and environment variables to use in its execve() call. This would allow user-supplied argument/environment variable lists to trigger a buffer overrun. EPSS estimates a 2.15% chance of exploitation in the next 30 days.
Description
The "process-execute" and "process-spawn" procedures in CHICKEN Scheme used fixed-size buffers for holding the arguments and environment variables to use in its execve() call. This would allow user-supplied argument/environment variable lists to trigger a buffer overrun. This affects all releases of CHICKEN up to and including 4.11 (it will be fixed in 4.12 and 5.0, which are not yet released).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Call-Cc | Chicken | <= 4.11.0 |
References
- http://lists.nongnu.org/archive/html/chicken-announce/2016-08/msg00001.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/92550Third Party Advisory, VDB Entry
- http://lists.nongnu.org/archive/html/chicken-announce/2016-08/msg00001.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/92550Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-6830?
How severe is CVE-2016-6830?
How do I fix CVE-2016-6830?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-6824Huawei AC6003, AC6005, AC6605, and ACU2 access controllers w…
- CVE-2016-6825Huawei XH620 V3, XH622 V3, and XH628 V3 servers with softwar…
- CVE-2016-6826Huawei AnyMail before 2.6.0301.0060 allows remote attackers …
- CVE-2016-6827Huawei FusionCompute before V100R005C10CP7002 stores clearte…
- CVE-2016-6828The tcp_check_send_head function in include/net/tcp.h in the…
- CVE-2016-6829The trove service user in (1) Openstack deployment (aka crow…9.8
- CVE-2016-6831The "process-execute" and "process-spawn" procedures did not…
- CVE-2016-6832Heap-based buffer overflow in the ff_audio_resample function…
- CVE-2016-6833Use-after-free vulnerability in the vmxnet3_io_bar0_write fu…4.4
- CVE-2016-6834The net_tx_pkt_do_sw_fragmentation function in hw/net/net_tx…4.4
- CVE-2016-6835The vmxnet_tx_pkt_parse_headers function in hw/net/vmxnet_tx…6
- CVE-2016-6836The vmxnet3_complete_packet function in hw/net/vmxnet3.c in …6
Are you affected by CVE-2016-6830?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
