Arbitrary code execution - CVE-2016-0913

 

Arbitrary code execution - CVE-2016-0913

Published: October 5, 2016 / Updated: October 5, 2016


Vulnerability identifier: #VU762
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-0913
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause arbitrary code execution on the target language.
The weakness is caused by insufficient validation of input. Under the guise of Replication Manager (RM) server attackers can link to the target RM user and trick the victim to load from an SMB share a specially crafted file containing arbitrary code.
Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.



Affected software

SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Workstation Extension 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Package Hub 15
openSUSE Leap
MozillaThunderbird
MozillaThunderbird-translations-common
MozillaThunderbird-debuginfo
MozillaThunderbird-translations-other
MozillaThunderbird-debugsource

How to mitigate CVE-2016-0913


MozillaThunderbird - update to 115.12.2-150200.8.168.1
MozillaThunderbird-translations-common - update to 115.12.2-150200.8.168.1
MozillaThunderbird-debuginfo - update to 115.12.2-150200.8.168.1
MozillaThunderbird-translations-other - update to 115.12.2-150200.8.168.1
MozillaThunderbird-debugsource - update to 115.12.2-150200.8.168.1

External References

Related Security Bulletins