NULL pointer dereference in libgsf - CVE-2016-9888

 

NULL pointer dereference in libgsf - CVE-2016-9888

Published: December 8, 2016 / Updated: July 28, 2020


Vulnerability identifier: #VU32194
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9888
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error. A remote attacker can trigger denial of service conditions via a crafted TAR file.


Affected software

libgsf
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12 SP5 LTSS
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
Fedora
libgsf (Alpine package)
libgsf
libgsf-1-114-debuginfo
libgsf-debugsource
libgsf-1-114
libgsf-lang
libgsf-1-114-debuginfo-32bit
libgsf-1-114-32bit
mingw-libgsf
IBM Tivoli Storage Manager

How to mitigate CVE-2016-9888

Update to version 1.14.41.

libgsf - update to 1.14.41
libgsf (Alpine package) - update to 1.14.41-r0
libgsf - addressed in versions 1.14.33-3.fc23, 1.14.33-4.fc24, 1.14.33-4.fc25
libgsf-1-114-debuginfo - update to 1.14.40-8.3.1
libgsf-debugsource - update to 1.14.40-8.3.1
libgsf-1-114 - update to 1.14.40-8.3.1
libgsf-lang - update to 1.14.40-8.3.1
libgsf-1-114-debuginfo-32bit - update to 1.14.40-8.3.1
libgsf-1-114-32bit - update to 1.14.40-8.3.1
mingw-libgsf - update to 1.14.41-1.fc25

External References

Related Security Bulletins