PT-2016-7862 · Gnome+2 · Gnome Structured File Library+2

Behzad Najjarpour Jabbari

·

Published

2016-12-06

·

Updated

2024-10-29

·

CVE-2016-9888

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNOME Structured File Library versions prior to 1.14.41
Description The issue is related to an error within the tar directory for file() function in the gsf-infile-tar.c file, which can be exploited to trigger a Null pointer dereference, causing a crash when processing a crafted TAR file.
Recommendations For versions prior to 1.14.41, update to version 1.14.41 or later to resolve the issue. As a temporary workaround, consider avoiding the use of crafted TAR files that could trigger the Null pointer dereference in the tar directory for file() function until a patch is applied.

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2417
CVE-2016-9888
DLA-2183-1
DLA-740-1
MGASA-2016-0427
SUSE-SU-2024:3770-1
SUSE-SU-2024_3770-1

Affected Products

Alt Linux
Gnome Structured File Library
Suse