Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2016-10253
issue was discovered in Erlang/OTP 18.x.
Technology
Erlang/OTP
CVSS Score
9.8 / 10.0
Affected Versions
18.0; 18.0.1; 18.0.2; 18.0.3
Upstream Fix
See upstream advisory
Published
March 18, 2017
OSSeva Coverage
Fixed upstream
Description
An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions using a malformed extpattern can indirectly specify an offset that is used as an array index. This ordinal permits arbitrary regions within the erts_alloc arena to be both read and written to.
Is your Erlang/OTP deployment affected?
If you're running 18.0; 18.0.1; 18.0.2; 18.0.3, you need this patch. Book a discovery call to get covered.