CVE-2016-6318: Cracklib Project Cracklib
High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges via a long GECOS field, involving longbuffer.
Affected products
- Cracklib Project Cracklib: from 2.9.0, before 2.9.6 (fixed in 2.9.6)
- Debian Debian Linux: version 8.0 only
- Opensuse Leap: version 42.1 only
Published 2016-09-07. Last modified 2026-06-17.