Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9888

Опубликовано: 07 дек. 2016
Источник: redhat
CVSS3: 3.3
CVSS2: 4.3

Описание

An error within the "tar_directory_for_file()" function (gsf-infile-tar.c) in GNOME Structured File Library before 1.14.41 can be exploited to trigger a Null pointer dereference and subsequently cause a crash via a crafted TAR file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libgsfWill not fix
Red Hat Enterprise Linux 6libgsfWill not fix
Red Hat Enterprise Linux 7libgsfWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1403198libgsf: Null pointer dereference in tar_directory_for_file()

3.3 Low

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 9 лет назад

An error within the "tar_directory_for_file()" function (gsf-infile-tar.c) in GNOME Structured File Library before 1.14.41 can be exploited to trigger a Null pointer dereference and subsequently cause a crash via a crafted TAR file.

CVSS3: 5.5
nvd
около 9 лет назад

An error within the "tar_directory_for_file()" function (gsf-infile-tar.c) in GNOME Structured File Library before 1.14.41 can be exploited to trigger a Null pointer dereference and subsequently cause a crash via a crafted TAR file.

CVSS3: 5.5
debian
около 9 лет назад

An error within the "tar_directory_for_file()" function (gsf-infile-ta ...

CVSS3: 5.5
github
больше 3 лет назад

An error within the "tar_directory_for_file()" function (gsf-infile-tar.c) in GNOME Structured File Library before 1.14.41 can be exploited to trigger a Null pointer dereference and subsequently cause a crash via a crafted TAR file.

suse-cvrf
больше 1 года назад

Security update for libgsf

3.3 Low

CVSS3

4.3 Medium

CVSS2