{"id":"CVE-2016-6855","details":"Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup.","modified":"2026-07-08T05:48:16.117368587Z","published":"2016-09-07T18:59:05.703Z","related":["SUSE-SU-2016:2827-1","openSUSE-SU-2024:10170-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"12.04"},{"last_affected":"12.04"},{"introduced":"14.04"},{"last_affected":"14.04"},{"introduced":"16.04"},{"last_affected":"16.04"}],"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux","cpes":["cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*"]},{"extracted_events":[{"introduced":"23"},{"last_affected":"23"},{"introduced":"24"},{"last_affected":"24"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora","cpes":["cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*"]},{"vendor_product":"gnome:eye_of_gnome","cpes":["cpe:2.3:a:gnome:eye_of_gnome:3.16.5:*:*:*:*:*:*:*","cpe:2.3:a:gnome:eye_of_gnome:3.17.1:*:*:*:*:*:*:*","cpe:2.3:a:gnome:eye_of_gnome:3.17.2:*:*:*:*:*:*:*","cpe:2.3:a:gnome:eye_of_gnome:3.17.3:*:*:*:*:*:*:*","cpe:2.3:a:gnome:eye_of_gnome:3.17.90:*:*:*:*:*:*:*","cpe:2.3:a:gnome:eye_of_gnome:3.17.91:*:*:*:*:*:*:*","cpe:2.3:a:gnome:eye_of_gnome:3.17.92:*:*:*:*:*:*:*","cpe:2.3:a:gnome:eye_of_gnome:3.18.0:*:*:*:*:*:*:*","cpe:2.3:a:gnome:eye_of_gnome:3.18.1:*:*:*:*:*:*:*","cpe:2.3:a:gnome:eye_of_gnome:3.18.2:*:*:*:*:*:*:*","cpe:2.3:a:gnome:eye_of_gnome:3.19.1:*:*:*:*:*:*:*","cpe:2.3:a:gnome:eye_of_gnome:3.19.2:*:*:*:*:*:*:*","cpe:2.3:a:gnome:eye_of_gnome:3.19.3:*:*:*:*:*:*:*","cpe:2.3:a:gnome:eye_of_gnome:3.19.4:*:*:*:*:*:*:*","cpe:2.3:a:gnome:eye_of_gnome:3.19.90:*:*:*:*:*:*:*","cpe:2.3:a:gnome:eye_of_gnome:3.19.91:*:*:*:*:*:*:*","cpe:2.3:a:gnome:eye_of_gnome:3.19.92:*:*:*:*:*:*:*","cpe:2.3:a:gnome:eye_of_gnome:3.20.0:*:*:*:*:*:*:*","cpe:2.3:a:gnome:eye_of_gnome:3.20.1:*:*:*:*:*:*:*","cpe:2.3:a:gnome:eye_of_gnome:3.20.2:*:*:*:*:*:*:*","cpe:2.3:a:gnome:eye_of_gnome:3.20.3:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.16.5"},{"last_affected":"3.16.5"},{"introduced":"3.17.1"},{"last_affected":"3.17.1"},{"introduced":"3.17.2"},{"last_affected":"3.17.2"},{"introduced":"3.17.3"},{"last_affected":"3.17.3"},{"introduced":"3.17.90"},{"last_affected":"3.17.90"},{"introduced":"3.17.91"},{"last_affected":"3.17.91"},{"introduced":"3.17.92"},{"last_affected":"3.17.92"},{"introduced":"3.18.0"},{"last_affected":"3.18.0"},{"introduced":"3.18.1"},{"last_affected":"3.18.1"},{"introduced":"3.18.2"},{"last_affected":"3.18.2"},{"introduced":"3.19.1"},{"last_affected":"3.19.1"},{"introduced":"3.19.2"},{"last_affected":"3.19.2"},{"introduced":"3.19.3"},{"last_affected":"3.19.3"},{"introduced":"3.19.4"},{"last_affected":"3.19.4"},{"introduced":"3.19.90"},{"last_affected":"3.19.90"},{"introduced":"3.19.91"},{"last_affected":"3.19.91"},{"introduced":"3.19.92"},{"last_affected":"3.19.92"},{"introduced":"3.20.0"},{"last_affected":"3.20.0"},{"introduced":"3.20.1"},{"last_affected":"3.20.1"},{"introduced":"3.20.2"},{"last_affected":"3.20.2"},{"introduced":"3.20.3"},{"last_affected":"3.20.3"}],"source":"CPE_STRING"},{"vendor_product":"opensuse:leap","cpes":["cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"42.1"},{"last_affected":"42.1"}],"source":"CPE_STRING"},{"vendor_product":"opensuse:opensuse","cpes":["cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"13.2"},{"last_affected":"13.2"}],"source":"CPE_STRING"},{"source":"DESCRIPTION","extracted_events":[{"introduced":"3.18.x"},{"fixed":"3.18.3"},{"introduced":"3.20.x"},{"fixed":"3.20.4"}]}]},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2020/04/msg00018.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JVINHHR6VJKXTYYMAYKN5GROKHVT4UKB/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T6GFDHLNPUG7JHWM3QLXQNRA7NZGU2KI/"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/40291/"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-updates/2016-09/msg00021.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/92616"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-3069-1"},{"type":"ADVISORY","url":"https://git.gnome.org/browse/eog/plain/NEWS?h=3.16.5"},{"type":"ADVISORY","url":"https://git.gnome.org/browse/eog/plain/NEWS?h=3.18.3"},{"type":"ADVISORY","url":"https://git.gnome.org/browse/eog/plain/NEWS?h=3.20.4"},{"type":"REPORT","url":"https://bugzilla.gnome.org/show_bug.cgi?id=770143"},{"type":"FIX","url":"https://git.gnome.org/browse/eog/commit/?id=e99a8c00f959652fe7c10e2fa5a3a7a5c25e6af4"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/138486/Gnome-Eye-Of-Gnome-3.10.2-Out-Of-Bounds-Write.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gnome/glib","events":[{"introduced":"0"},{"fixed":"285c2534f4c5117fb726179d3bdc49ca1aafb9b9"}],"database_specific":{"source":"DESCRIPTION","extracted_events":[{"introduced":"0"},{"fixed":"2.44.1"}]}}],"versions":["2.44.0","2.43.92","2.43.91","2.43.90","2.43.4","2.43.3","2.43.2","2.43.1","2.43.0","2.42.0","2.41.5","2.41.4","2.41.3","2.41.2","2.41.1","2.39.92","2.39.91","2.39.90","2.39.4","2.39.3","2.39.2","2.39.1","2.39.0","2.38.0","2.37.93","2.37.92","2.37.7","2.37.6","2.37.5","2.37.4","2.37.3","2.37.2","2.37.1","2.37.0","2.36.0","2.35.9","2.35.8","2.35.7","2.35.6","2.35.4","2.35.3","2.35.2","2.35.1","2.34.0","2.33.14","2.33.12","2.33.10","2.33.8","2.33.6","2.33.4","2.33.3","2.33.2","2.33.1","2.32.1","2.32.0","2.31.22","2.31.20","2.31.18","2.31.16","2.31.14","2.31.12","2.31.10","2.31.8","2.31.6","2.31.4","2.31.2","2.31.0","2.29.90","2.29.18","2.29.16","2.29.14","2.29.12","2.29.10","2.29.8","2.29.6","2.29.4","2.28.0","2.27.93","2.27.92","2.27.91","2.27.90","2.27.5","2.27.3","2.27.2","2.27.1","2.27.0","2.25.15","2.25.14","2.25.13","2.25.12","2.25.11","2.25.10","2.25.9","2.25.8","glib-2.25.7","2.25.6","2.25.5","2.25.4","2.24.0","2.20.0","2.25.3","2.25.2","2.25.0","2.23.6","2.23.5","2.23.4","2.23.3","2.23.2","2.23.1","2.23.0","2.22.2","2.22.0","2.21.6","2.21.5","2.21.4","2.21.3","2.21.2","2.21.1","2.20.1","GLIB_2_20_0","GLIB_2_19_10","GLIB_2_19_9","GLIB_2_19_8","GLIB_2_19_7","GLIB_2_19_6","GLIB_2_19_5","GLIB_2_19_4","GLIB_2_19_3","GLIB_2_19_2","GLIB_2_19_1","GLIB_2_19_0","GLIB_2_18_1","GLIB_2_18_0","GLIB_2_17_7","GLIB_2_17_6","GLIB_2_17_5","GLIB_2_17_4","GLIB_2_17_3","GLIB_2_17_2","GLIB_2_17_1","GLIB_2_17_0","GLIB_2_16_1","GLIB_2_15_6","GLIB_2_15_5","GLIB_2_15_4","GLIB_2_15_3","GLIB_2_15_2","GLIB_2_15_1","GLIB_2_14_3","GLIB_2_14_2","GLIB_2_14_1","GLIB_2_14_0","GLIB_2_13_7","GLIB_2_13_6","GLIB_2_13_5","GLIB_2_13_3","GLIB_2_13_2","GLIB_2_13_1","GLIB_2_13_0","glib-2-12-branchpoint","GLIB_2_12_2","GLIB_2_12_1","GLIB_2_12_0","GLIB_2_11_4","GLIB_2_11_3","GLIB_2_11_2","GLIB_2_11_1","GLIB_2_11_0","glib-2-10-branchpoint","GLIB_2_10_1","GLIB_2_10_0","GLIB_2_9_6","GLIB_2_9_5","GLIB_2_9_4","GLIB_2_9_3","GLIB_2_9_2","GLIB_2_9_1","GLIB_2_9_0","GLIB_2_8_1","GLIB_2_8_0","GLIB_2_7_7","GLIB_2_7_6","GLIB_2_7_5","GLIB_2_7_4","GTK_2_7_4","GLIB_2_7_3","GLIB_2_7_2","GLIB_2_7_1","GLIB_2_7_0","glib-2-6-branchpoint","GLIB_2_6_1","GLIB_2_6_0","GLIB_2_5_6","gobject_0_10_0","GLIB_2_5_5","GTK_2_5_4","GLIB_2_5_3","GLIB_2_5_2","GLIB_2_5_1","GLIB_2_5_0","gobject_0_9_0","glib-2-4-branchpoint","GLIB_2_4_1","GLIB_2_4_0","GLIB_2_3_6","GLIB_2_3_5","GLIB_2_3_3","GLIB_2_3_2","start","GLIB_2_3_1","GLIB_2_3_0","glib-2-2-branchpoint","GLIB_2_2_0","GLIB_2_1_5","GLIB_2_1_4","GLIB_2_1_3","R_2_0_core","glib-2-0-branchpoint","GLIB_2_0_1","GLIB_2_0_0","GLIB_2_0_0_RC1","GLIB_1_3_15","GLIB_1_3_14","GLIB_1_3_13","GLIB_1_3_12","GLIB_1_3_11","GOBJECT_GType_guint","GLIB_1_3_10","GLIB_1_3_9","GLIB_1_3_8","GLIB_1_3_7","GTK_ALL_1_3_6","GLIB_1_3_6","GLIB_1_3_5","GLIB_1_3_4","GLIB_1_3_3","GLIB_1_2_9PRE1","GLIB_1_3_2","GNOME_PRINT_0_24","GLIB_1_3_1","GLIB_1_3_0","GLIB_1_2_0","GLIB_1_1_16","GLIB_1_1_15","GLIB_1_1_14","GLIB_1_1_13","GLIB_1_1_12","GLIB_1_1_11","GLIB_1_1_10","GLIB_GNOME_0_99_1","FOR_GNOME_0_99_1","GLIB_1_1_9","GLIB_1_1_8a","GLIB_1_1_8","GLIB_1_1_7","GLIB_1_1_6","PRE_CLEANUP","GLIB_1_1_5","GLIB_1_1_4","GLIB_VERSION_1_1_3","GLIB_1_1_3a","GLIB_1_1_3","GLIB_1_1_2","GLIB_1_1_1","GLIB_1_1_0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-6855.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}