Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 494
Alerts This Week
Warning Icon 1 494

Debian Jessie DSA-3653-2 Critical: Flex Buffer Overflow Fix

debian
Calendar Grey September 4, 2016
Scroller Debian
The Debian Security Advisory DSA-3654-1 notifies users of a crucial update to the libpng library addressing a severe vulnerability and its effects on system integrity
It was reported that the update for flex as released in DSA-3653-1 did not completely address CVE-2016-6354 as intended due to problems in the patch handling and regenerated files ...

Summary

Alexander Sulfrian discovered a buffer overflow in the
yy_get_next_buffer() function generated by Flex, which may result in
denial of service and potentially the execution of code if operating on
data from untrusted sources.

Affected applications need to be rebuild.

For the stable distribution (jessie), this problem has been fixed in
version 2.5.39-8+deb8u2.

We recommend that you upgrade your flex packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: flex
CVE ID: CVE-2016-6354

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.