CVE-2016-6855
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 18.9%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 18.86% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- fedoraproject/fedora · opensuse/leap · opensuse/opensuse · canonical/ubuntu linux · gnome/eye of gnome
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-updates/2016-09/msg00021.htmlThird Party Advisory
- http://packetstormsecurity.com/files/138486/Gnome-Eye-Of-Gnome-3.10.2-Out-Of-Bounds-Write.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/92616Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-3069-1Third Party Advisory
- https://bugzilla.gnome.org/show_bug.cgi?id=770143Issue Tracking
- https://git.gnome.org/browse/eog/commit/?id=e99a8c00f959652fe7c10e2fa5a3a7a5c25e6af4Issue Tracking, Patch
- https://git.gnome.org/browse/eog/plain/NEWS?h=3.16.5Release Notes
- https://git.gnome.org/browse/eog/plain/NEWS?h=3.18.3Release Notes
- https://git.gnome.org/browse/eog/plain/NEWS?h=3.20.4Release Notes
- https://lists.debian.org/debian-lts-announce/2020/04/msg00018.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JVINHHR6VJKXTYYMAYKN5GROKHVT4UKB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T6GFDHLNPUG7JHWM3QLXQNRA7NZGU2KI/
- https://www.exploit-db.com/exploits/40291/
- http://lists.opensuse.org/opensuse-updates/2016-09/msg00021.htmlThird Party Advisory
- http://packetstormsecurity.com/files/138486/Gnome-Eye-Of-Gnome-3.10.2-Out-Of-Bounds-Write.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/92616Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-3069-1Third Party Advisory
- https://bugzilla.gnome.org/show_bug.cgi?id=770143Issue Tracking
- https://git.gnome.org/browse/eog/commit/?id=e99a8c00f959652fe7c10e2fa5a3a7a5c25e6af4Issue Tracking, Patch
- https://git.gnome.org/browse/eog/plain/NEWS?h=3.16.5Release Notes
- https://git.gnome.org/browse/eog/plain/NEWS?h=3.18.3Release Notes
- https://git.gnome.org/browse/eog/plain/NEWS?h=3.20.4Release Notes
- https://lists.debian.org/debian-lts-announce/2020/04/msg00018.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JVINHHR6VJKXTYYMAYKN5GROKHVT4UKB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T6GFDHLNPUG7JHWM3QLXQNRA7NZGU2KI/
- https://www.exploit-db.com/exploits/40291/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.