Arbitrary code execution - CVE-2016-5684

 

Arbitrary code execution - CVE-2016-5684

Published: October 17, 2016 / Updated: February 1, 2018


Vulnerability identifier: #VU1005
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5684
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated user to execute arbitrary code on the target system.
The weakness exists due to buffer overflow caused by processing of malformed XMP or RAW image and allowing attackers to execute arbitrary code.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.

Affected software

Gentoo Linux
Fedora
Opensuse
freeimage (Ubuntu package)
media-libs/freeimage
freeimage
mingw-freeimage
Oracle Hospitality Cruise Shipboard Property Management System

How to mitigate CVE-2016-5684

Update stable distribution (jessie) to 3.15.4-4.2+deb8u1.

Update testing distribution (stretch) to 3.17.0+ds1-3.

Update unstable distribution (sid) to3.17.0+ds1-3.


freeimage (Ubuntu package) - addressed in versions 3.15.4-3ubuntu0.1, 3.17.0+ds1-2ubuntu0.1
media-libs/freeimage - update to 3.15.4-r1
freeimage - addressed in versions 3.17.0-4.el7, 3.17.0-7.fc23, 3.17.0-7.fc24, 3.17.0-7.fc25
mingw-freeimage - addressed in versions 3.17.0-4.fc23, 3.17.0-4.fc24, 3.17.0-4.fc25

External References

Related Security Bulletins