CVE-2016-6855
CVE-2016-6855
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/138486/Gnome-Eye-Of-Gnome-3.10.2-Out-Of-Bounds-Write.htmlunverifiedcve_referencewww.exploit-db.com/exploits/40291/unverifiedexploitdbwww.exploit-db.com/exploits/40291unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://lists.opensuse.org/opensuse-updates/2016-09/msg00021.htmlhttp://packetstormsecurity.com/files/138486/Gnome-Eye-Of-Gnome-3.10.2-Out-Of-Bounds-Write.htmlhttps://bugzilla.gnome.org/show_bug.cgi?id=770143https://git.gnome.org/browse/eog/commit/?id=e99a8c00f959652fe7c10e2fa5a3a7a5c25e6af4https://git.gnome.org/browse/eog/plain/NEWS?h=3.16.5https://git.gnome.org/browse/eog/plain/NEWS?h=3.18.3https://git.gnome.org/browse/eog/plain/NEWS?h=3.20.4https://lists.debian.org/debian-lts-announce/2020/04/msg00018.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JVINHHR6VJKXTYYMAYKN5GROKHVT4UKB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T6GFDHLNPUG7JHWM3QLXQNRA7NZGU2KI/https://www.exploit-db.com/exploits/40291/http://www.securityfocus.com/bid/92616