Vulnerability Description
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fedoraproject | Fedora | 23 |
| Opensuse | Leap | 42.1 |
| Opensuse | Opensuse | 13.2 |
| Canonical | Ubuntu Linux | 12.04 |
| Gnome | Eye Of Gnome | 3.16.5 |
| Gnome | Glib | 2.44.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-updates/2016-09/msg00021.htmlThird Party Advisory
- http://packetstormsecurity.com/files/138486/Gnome-Eye-Of-Gnome-3.10.2-Out-Of-BouExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/92616Third Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-3069-1Third Party Advisory
- https://bugzilla.gnome.org/show_bug.cgi?id=770143Issue Tracking
- https://git.gnome.org/browse/eog/commit/?id=e99a8c00f959652fe7c10e2fa5a3a7a5c25eIssue TrackingPatch
- https://git.gnome.org/browse/eog/plain/NEWS?h=3.16.5Release Notes
- https://git.gnome.org/browse/eog/plain/NEWS?h=3.18.3Release Notes
- https://git.gnome.org/browse/eog/plain/NEWS?h=3.20.4Release Notes
- https://lists.debian.org/debian-lts-announce/2020/04/msg00018.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://www.exploit-db.com/exploits/40291/
- http://lists.opensuse.org/opensuse-updates/2016-09/msg00021.htmlThird Party Advisory
- http://packetstormsecurity.com/files/138486/Gnome-Eye-Of-Gnome-3.10.2-Out-Of-BouExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2016-6855?
CVE-2016-6855 is a vulnerability with a CVSS score of 7.5 (HIGH). Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds wri...
How severe is CVE-2016-6855?
CVE-2016-6855 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-6855?
Check the references section above for vendor advisories and patch information. Affected products include: Fedoraproject Fedora, Opensuse Leap, Opensuse Opensuse, Canonical Ubuntu Linux, Gnome Eye Of Gnome.