Name | CVE-2016-6855 |
Description | Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-2185-1, DLA-605-1 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
eog (PTS) | bullseye | 3.38.2-1 | fixed |
bookworm | 43.2-1 | fixed | |
trixie, sid | 47.0-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
eog | source | wheezy | 3.4.2-1+build1+deb7u1 | DLA-605-1 | ||
eog | source | jessie | 3.14.1-1+deb8u1 | DLA-2185-1 | ||
eog | source | (unstable) | 3.20.4-1 |
https://bugzilla.gnome.org/show_bug.cgi?id=770143
https://git.gnome.org/browse/eog/commit/?id=e99a8c00f959652fe7c10e2fa5a3a7a5c25e6af4