Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2016-10253

issue was discovered in Erlang/OTP 18.x.

Technology

Erlang/OTP

CVSS Score

9.8 / 10.0

Affected Versions

18.0; 18.0.1; 18.0.2; 18.0.3

Upstream Fix

See upstream advisory

Published

March 18, 2017

OSSeva Coverage

Fixed upstream

Description

An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions using a malformed extpattern can indirectly specify an offset that is used as an array index. This ordinal permits arbitrary regions within the erts_alloc arena to be both read and written to.

Is your Erlang/OTP deployment affected?

If you're running 18.0; 18.0.1; 18.0.2; 18.0.3, you need this patch. Book a discovery call to get covered.