PT-2016-7146 · Gnome+3 · Glib+4

Kaslov Dmitri

·

Published

2016-08-21

·

Updated

2024-06-15

·

CVE-2016-6855

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Eye of GNOME versions 3.16.5 through 3.17.x Eye of GNOME versions 3.18.x through 3.18.2 Eye of GNOME version 3.19.x Eye of GNOME versions 3.20.x through 3.20.3
Description The issue allows remote attackers to cause a denial of service, resulting in an out-of-bounds write and crash. This is achieved by passing invalid UTF-8 to GMarkup.
Recommendations For Eye of GNOME version 3.16.5, update to a version later than 3.16.5 or ensure glib is updated to version 2.44.1 or later. For Eye of GNOME versions 3.17.x, update to a version later than 3.17.x or ensure glib is updated to version 2.44.1 or later. For Eye of GNOME versions 3.18.x through 3.18.2, update to version 3.18.3 or later, or ensure glib is updated to version 2.44.1 or later. For Eye of GNOME version 3.19.x, update to a version later than 3.19.x or ensure glib is updated to version 2.44.1 or later. For Eye of GNOME versions 3.20.x through 3.20.3, update to version 3.20.4 or later, or ensure glib is updated to version 2.44.1 or later.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1868
CVE-2016-6855
DLA-2185-1
DLA-605-1
MGASA-2016-0297
OPENSUSE-SU-2024:10170-1
SUSE-SU-2016:2827-1
SUSE-SU-2016_2827-1
USN-3069-1

Affected Products

Alt Linux
Eye Of Gnome
Suse
Ubuntu
Glib