CVE-2016-4478

Source
https://cve.org/CVERecord?id=CVE-2016-4478
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-4478.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-4478
Downstream
Related
Published
2016-06-13T19:59:09Z
Modified
2026-07-08T12:41:31Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers to cause a denial of service via vectors related to XMLRPC response encoding.

Database specific
{
    "unresolved_ranges":  [
        {
            "cpes":  [
                "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "8.0"
                },
                {
                    "last_affected":  "8.0"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "debian:debian_linux"
        },
        {
            "cpes":  [
                "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "42.1"
                },
                {
                    "last_affected":  "42.1"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "opensuse:leap"
        },
        {
            "cpes":  [
                "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "13.2"
                },
                {
                    "last_affected":  "13.2"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "opensuse:opensuse"
        }
    ]
}
References

Affected packages

Git / github.com/atheme/atheme

Affected ranges

Type
GIT
Repo
https://github.com/atheme/atheme
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:atheme:atheme:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "last_affected":  "7.2.6"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

atheme-6.*
atheme-6.0.0-alpha1
atheme-7.*
atheme-7.2.0
atheme-7.2.0-beta1
atheme-7.2.0-beta2
atheme-7.2.0-rc1
atheme-7.2.0-rc2
atheme-7.2.1
atheme-7.2.2
atheme-7.2.3
atheme-7.2.4
atheme-7.2.5
atheme-7.2.6
atheme-services-3.*
atheme-services-3.0.0
atheme-services-3.0.1
atheme-services-3.0.2
atheme-services-3.0.3
atheme-services-4.*
atheme-services-4.0.0
atheme-services-4.0.1
atheme-services-5.*
atheme-services-5.0
atheme-services-5.0-beta1
atheme-services-5.0.1
atheme-services-5.1-rc1
atheme-services-5.1.0
atheme-services-5.1.1
atheme-services-5.2.0
atheme-services-6.*
atheme-services-6.0.0
atheme-services-6.0.0-alpha2
atheme-services-6.0.0-alpha3
atheme-services-6.0.0-alpha6
atheme-services-6.0.0-alpha7
atheme-services-6.0.0-beta1
atheme-services-6.0.0-beta2
atheme-services-6.0.0-beta3
atheme-services-6.0.0-rc1
atheme-services-6.0.0-rc2
atheme-services-7.*
atheme-services-7.0-alpha1
atheme-services-7.0.0-alpha10
atheme-services-7.0.0-alpha11
atheme-services-7.0.0-alpha13
atheme-services-7.0.0-alpha13.37
atheme-services-7.0.0-alpha14
atheme-services-7.0.0-alpha2
atheme-services-7.0.0-alpha3
atheme-services-7.0.0-alpha6
atheme-services-7.0.0-alpha7
atheme-services-7.0.0-alpha8
atheme-services-7.0.0-alpha9
atheme-services-7.0.0-beta1
atheme-services-7.0.0-beta2
atheme-services-7.1.0-alpha1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-4478.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "42205439419379173217561027574847435756",
                "279842839254015645750451448363378502239",
                "130012205762668577428285411191529094442",
                "83917961357696884801576035593535001229",
                "211077350756679990206601574942213543167"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2016-4478-34f02fe3",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/atheme/atheme/commit/87580d767868360d2fed503980129504da84b63e",
        "target":  {
            "file":  "modules/transport/xmlrpc/xmlrpclib.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "291135090142418443225470849783248172328",
            "length":  795
        },
        "id":  "CVE-2016-4478-c2d77b15",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/atheme/atheme/commit/87580d767868360d2fed503980129504da84b63e",
        "target":  {
            "file":  "modules/transport/xmlrpc/xmlrpclib.c",
            "function":  "xmlrpc_char_encode"
        }
    }
]
vanir_signatures_modified
"2026-07-08T12:41:31Z"