openSUSE-SU-2016:2242Vendor advisory
http://lists.opensuse.org/opensuse-updates/2016-09/msg00021.html CVE-2016-6855
HIGH
Eye of Gnome 3.10.2 - GMarkup Out of Bounds Write
Record summary
CVE-2016-6855 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBEye of Gnome 3.10.2 - GMarkup Out of Bounds WriteExploitDB exploitby Kaslov DmitriNot analyzed1 file
References
Showing 12 of 16packetstormsecurity.com
http://packetstormsecurity.com/files/138486/Gnome-Eye-Of-Gnome-3.10.2-Out-Of-Bounds-Write.html 92616vdb entry
http://www.securityfocus.com/bid/92616 USN-3069-1Vendor advisory
http://www.ubuntu.com/usn/USN-3069-1 bugzilla.gnome.orgConfirmation
https://bugzilla.gnome.org/show_bug.cgi?id=770143 git.gnome.orgConfirmation
https://git.gnome.org/browse/eog/commit?id=e99a8c00f959652fe7c10e2fa5a3a7a5c25e6af4 git.gnome.orgConfirmation
https://git.gnome.org/browse/eog/plain/NEWS?h=3.16.5 git.gnome.orgConfirmation
https://git.gnome.org/browse/eog/plain/NEWS?h=3.18.3 git.gnome.orgConfirmation
https://git.gnome.org/browse/eog/plain/NEWS?h=3.20.4 [debian-lts-announce] 20200425 [SECURITY] [DLA 2185-1] eog security updatemailing list
https://lists.debian.org/debian-lts-announce/2020/04/msg00018.html FEDORA-2016-5abbc35b6aVendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JVINHHR6VJKXTYYMAYKN5GROKHVT4UKB FEDORA-2016-0f8779baa6Vendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T6GFDHLNPUG7JHWM3QLXQNRA7NZGU2KI