7.5

CVE-2016-6855

Exploit
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version 23
Fedoraproject ≫ Fedora Version 24
Opensuse ≫ Leap Version 42.1
Opensuse ≫ Opensuse Version 13.2
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Gnome ≫ Eye Of Gnome Version 3.16.5
   Gnome ≫ Glib Version 2.44.0
Gnome ≫ Eye Of Gnome Version 3.17.1
   Gnome ≫ Glib Version 2.44.0
Gnome ≫ Eye Of Gnome Version 3.17.2
   Gnome ≫ Glib Version 2.44.0
Gnome ≫ Eye Of Gnome Version 3.17.3
   Gnome ≫ Glib Version 2.44.0
Gnome ≫ Eye Of Gnome Version 3.17.90
   Gnome ≫ Glib Version 2.44.0
Gnome ≫ Eye Of Gnome Version 3.17.91
   Gnome ≫ Glib Version 2.44.0
Gnome ≫ Eye Of Gnome Version 3.17.92
   Gnome ≫ Glib Version 2.44.0
Gnome ≫ Eye Of Gnome Version 3.18.0
   Gnome ≫ Glib Version 2.44.0
Gnome ≫ Eye Of Gnome Version 3.18.1
   Gnome ≫ Glib Version 2.44.0
Gnome ≫ Eye Of Gnome Version 3.18.2
   Gnome ≫ Glib Version 2.44.0
Gnome ≫ Eye Of Gnome Version 3.19.1
   Gnome ≫ Glib Version 2.44.0
Gnome ≫ Eye Of Gnome Version 3.19.2
   Gnome ≫ Glib Version 2.44.0
Gnome ≫ Eye Of Gnome Version 3.19.3
   Gnome ≫ Glib Version 2.44.0
Gnome ≫ Eye Of Gnome Version 3.19.4
   Gnome ≫ Glib Version 2.44.0
Gnome ≫ Eye Of Gnome Version 3.19.90
   Gnome ≫ Glib Version 2.44.0
Gnome ≫ Eye Of Gnome Version 3.19.91
   Gnome ≫ Glib Version 2.44.0
Gnome ≫ Eye Of Gnome Version 3.19.92
   Gnome ≫ Glib Version 2.44.0
Gnome ≫ Eye Of Gnome Version 3.20.0
   Gnome ≫ Glib Version 2.44.0
Gnome ≫ Eye Of Gnome Version 3.20.1
   Gnome ≫ Glib Version 2.44.0
Gnome ≫ Eye Of Gnome Version 3.20.2
   Gnome ≫ Glib Version 2.44.0
Gnome ≫ Eye Of Gnome Version 3.20.3
   Gnome ≫ Glib Version 2.44.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 18.86% 0.969
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://lists.opensuse.org/opensuse-updates/2016-09/msg00021.html
Third Party Advisory
http://packetstormsecurity.com/files/138486/Gnome-Eye-Of-Gnome-3.10.2-Out-Of-Bounds-Write.html
Third Party Advisory
Exploit
VDB Entry
http://www.securityfocus.com/bid/92616
Third Party Advisory
VDB Entry
http://www.ubuntu.com/usn/USN-3069-1
Third Party Advisory
https://bugzilla.gnome.org/show_bug.cgi?id=770143
Issue Tracking
https://git.gnome.org/browse/eog/commit/?id=e99a8c00f959652fe7c10e2fa5a3a7a5c25e6af4
Patch
Issue Tracking
https://git.gnome.org/browse/eog/plain/NEWS?h=3.16.5
Release Notes
https://git.gnome.org/browse/eog/plain/NEWS?h=3.18.3
Release Notes
https://git.gnome.org/browse/eog/plain/NEWS?h=3.20.4
Release Notes
https://lists.debian.org/debian-lts-announce/2020/04/msg00018.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JVINHHR6VJKXTYYMAYKN5GROKHVT4UKB/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T6GFDHLNPUG7JHWM3QLXQNRA7NZGU2KI/
https://www.exploit-db.com/exploits/40291/