Buffer overflow in the xmlrpccharencode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers to cause a denial of service via vectors related to XMLRPC response encoding.
[
{
"id": "CVE-2016-4478-34f02fe3",
"deprecated": false,
"target": {
"file": "modules/transport/xmlrpc/xmlrpclib.c"
},
"digest": {
"line_hashes": [
"42205439419379173217561027574847435756",
"279842839254015645750451448363378502239",
"130012205762668577428285411191529094442",
"83917961357696884801576035593535001229",
"211077350756679990206601574942213543167"
],
"threshold": 0.9
},
"source": "https://github.com/atheme/atheme/commit/87580d767868360d2fed503980129504da84b63e",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2016-4478-c2d77b15",
"deprecated": false,
"target": {
"function": "xmlrpc_char_encode",
"file": "modules/transport/xmlrpc/xmlrpclib.c"
},
"digest": {
"length": 795.0,
"function_hash": "291135090142418443225470849783248172328"
},
"source": "https://github.com/atheme/atheme/commit/87580d767868360d2fed503980129504da84b63e",
"signature_version": "v1",
"signature_type": "Function"
}
]