CVE-2016-10721
9.8
CRITICAL
CVSS 3.1
EPSS 2.2%
Description
partclone.restore in Partclone 0.2.87 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the partclone image header. An attacker may be able to execute arbitrary code in the context of the user running the affected application.
How to fix CVE-2016-10721
To remediate CVE-2016-10721, upgrade the affected package to a fixed version below.
- Debian/partclone—upgrade to 0.2.88-1 or later
Is CVE-2016-10721 being exploited?
Low — EPSS is 2.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.2.88-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |