Vulnerability Details CVE-2016-6830
The "process-execute" and "process-spawn" procedures in CHICKEN Scheme used fixed-size buffers for holding the arguments and environment variables to use in its execve() call. This would allow user-supplied argument/environment variable lists to trigger a buffer overrun. This affects all releases of CHICKEN up to and including 4.11 (it will be fixed in 4.12 and 5.0, which are not yet released).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.7%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2016-6830
-
cpe:2.3:a:call-cc:chicken:-
-
cpe:2.3:a:call-cc:chicken:3.0.0
-
cpe:2.3:a:call-cc:chicken:3.1.0
-
cpe:2.3:a:call-cc:chicken:3.2.0
-
cpe:2.3:a:call-cc:chicken:3.3.0
-
cpe:2.3:a:call-cc:chicken:3.4.0
-
cpe:2.3:a:call-cc:chicken:4.0.0
-
cpe:2.3:a:call-cc:chicken:4.1.0
-
cpe:2.3:a:call-cc:chicken:4.10.0
-
cpe:2.3:a:call-cc:chicken:4.11.0
-
cpe:2.3:a:call-cc:chicken:4.2.0
-
cpe:2.3:a:call-cc:chicken:4.3.0
-
cpe:2.3:a:call-cc:chicken:4.3.3
-
cpe:2.3:a:call-cc:chicken:4.3.4
-
cpe:2.3:a:call-cc:chicken:4.3.5
-
cpe:2.3:a:call-cc:chicken:4.3.6
-
cpe:2.3:a:call-cc:chicken:4.3.7
-
cpe:2.3:a:call-cc:chicken:4.4.0
-
cpe:2.3:a:call-cc:chicken:4.4.3
-
cpe:2.3:a:call-cc:chicken:4.4.4
-
cpe:2.3:a:call-cc:chicken:4.4.5
-
cpe:2.3:a:call-cc:chicken:4.4.6
-
cpe:2.3:a:call-cc:chicken:4.5.0
-
cpe:2.3:a:call-cc:chicken:4.5.2
-
cpe:2.3:a:call-cc:chicken:4.5.5
-
cpe:2.3:a:call-cc:chicken:4.5.6
-
cpe:2.3:a:call-cc:chicken:4.5.7
-
cpe:2.3:a:call-cc:chicken:4.6.0
-
cpe:2.3:a:call-cc:chicken:4.6.1
-
cpe:2.3:a:call-cc:chicken:4.6.2
-
cpe:2.3:a:call-cc:chicken:4.6.3
-
cpe:2.3:a:call-cc:chicken:4.6.5
-
cpe:2.3:a:call-cc:chicken:4.6.6
-
cpe:2.3:a:call-cc:chicken:4.6.7
-
cpe:2.3:a:call-cc:chicken:4.7.0
-
cpe:2.3:a:call-cc:chicken:4.7.0.6
-
cpe:2.3:a:call-cc:chicken:4.7.2
-
cpe:2.3:a:call-cc:chicken:4.7.3
-
cpe:2.3:a:call-cc:chicken:4.7.4
-
cpe:2.3:a:call-cc:chicken:4.8.0
-
cpe:2.3:a:call-cc:chicken:4.8.0.1
-
cpe:2.3:a:call-cc:chicken:4.8.0.2
-
cpe:2.3:a:call-cc:chicken:4.8.0.3
-
cpe:2.3:a:call-cc:chicken:4.8.0.4
-
cpe:2.3:a:call-cc:chicken:4.8.0.5
-
cpe:2.3:a:call-cc:chicken:4.8.0.6
-
cpe:2.3:a:call-cc:chicken:4.8.0.7
-
cpe:2.3:a:call-cc:chicken:4.8.1
-
cpe:2.3:a:call-cc:chicken:4.8.2
-
cpe:2.3:a:call-cc:chicken:4.9.0
-
cpe:2.3:a:call-cc:chicken:4.9.0.1
-
cpe:2.3:a:call-cc:chicken:4.9.1