PT-2016-7862 · Gnome+2 · Gnome Structured File Library+2
Behzad Najjarpour Jabbari
·
Published
2016-12-06
·
Updated
2024-10-29
·
CVE-2016-9888
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GNOME Structured File Library versions prior to 1.14.41
Description
The issue is related to an error within the
tar directory for file() function in the gsf-infile-tar.c file, which can be exploited to trigger a Null pointer dereference, causing a crash when processing a crafted TAR file.Recommendations
For versions prior to 1.14.41, update to version 1.14.41 or later to resolve the issue. As a temporary workaround, consider avoiding the use of crafted TAR files that could trigger the Null pointer dereference in the
tar directory for file() function until a patch is applied.Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Gnome Structured File Library
Suse