ALT-PU-2016-1868-1
Closed vulnerabilities
Published: 2016-09-07
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2016-6855
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup.
Severity: HIGH (7.5)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
- openSUSE-SU-2016:2242
- openSUSE-SU-2016:2242
- http://packetstormsecurity.com/files/138486/Gnome-Eye-Of-Gnome-3.10.2-Out-Of-Bounds-Write.html
- http://packetstormsecurity.com/files/138486/Gnome-Eye-Of-Gnome-3.10.2-Out-Of-Bounds-Write.html
- 92616
- 92616
- USN-3069-1
- USN-3069-1
- https://bugzilla.gnome.org/show_bug.cgi?id=770143
- https://bugzilla.gnome.org/show_bug.cgi?id=770143
- https://git.gnome.org/browse/eog/commit/?id=e99a8c00f959652fe7c10e2fa5a3a7a5c25e6af4
- https://git.gnome.org/browse/eog/commit/?id=e99a8c00f959652fe7c10e2fa5a3a7a5c25e6af4
- https://git.gnome.org/browse/eog/plain/NEWS?h=3.16.5
- https://git.gnome.org/browse/eog/plain/NEWS?h=3.16.5
- https://git.gnome.org/browse/eog/plain/NEWS?h=3.18.3
- https://git.gnome.org/browse/eog/plain/NEWS?h=3.18.3
- https://git.gnome.org/browse/eog/plain/NEWS?h=3.20.4
- https://git.gnome.org/browse/eog/plain/NEWS?h=3.20.4
- [debian-lts-announce] 20200425 [SECURITY] [DLA 2185-1] eog security update
- [debian-lts-announce] 20200425 [SECURITY] [DLA 2185-1] eog security update
- FEDORA-2016-5abbc35b6a
- FEDORA-2016-5abbc35b6a
- FEDORA-2016-0f8779baa6
- FEDORA-2016-0f8779baa6
- 40291
- 40291