PatchSiren

Debian CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Debian CVE published 2017-02-17

CVE-2017-6014

CVE-2017-6014 is a high-severity availability flaw in Wireshark’s STANAG 4607 parser. A crafted or malformed capture file can cause an infinite loop when a packet header’s size field is null, so the parser never advances its read offset and repeatedly processes the same zero-length packet until memory is exhausted. The NVD record maps affected Wireshark versions up to 2.2.4 and cites CWE-835.

MEDIUM Debian CVE published 2017-02-17

CVE-2016-9955

CVE-2016-9955 affects SimpleSAMLphp before 1.14.11. The issue is in the SimpleSAML_XML_Validator class constructor and stems from improper conversion of return values to boolean. According to the official descriptions, that flaw may let a remote attacker spoof signatures on SAML 1 responses or cause denial of service through memory consumption. NVD rates the issue MEDIUM with a CVSS v3.0 score of 6.3.

MEDIUM Debian CVE published 2017-02-15

CVE-2016-8692

CVE-2016-8692 is a denial-of-service vulnerability in JasPer’s JPEG 2000 decoder path. A crafted BMP image with an abnormal YRsiz value can trigger a divide-by-zero in jpc_dec_process_siz, causing the imginfo command to crash. The issue is tracked as CWE-369 and affects JasPer versions before 1.900.4.

MEDIUM Debian CVE published 2017-02-15

CVE-2016-8691

CVE-2016-8691 affects JasPer before 1.900.4 and can crash the imginfo command when it processes a crafted BMP image with a malicious XRsiz value. The issue is a denial of service only: the supplied NVD record classifies the weakness as CWE-369 and the CVSS impact as availability loss, not code execution or data theft.

HIGH Debian CVE published 2017-02-15

CVE-2016-8684

CVE-2016-8684 affects GraphicsMagick 1.3.25 when a crafted image triggers MagickMalloc in magick/memory.c to fail, leading to a truncation/error path described by NVD as a memory-safety issue (CWE-119). The CVE record was published on 2017-02-15, while the supplied references show patch and advisory activity in 2016 across upstream, distro, and community sources. NVD rates the issue CVSS 7.8 High.

HIGH Debian CVE published 2017-02-15

CVE-2016-8683

CVE-2016-8683 covers a flaw in GraphicsMagick 1.3.25’s ReadPCXImage function for PCX files. A crafted image can trigger a memory allocation failure and a file truncation error, which NVD classifies under CWE-119 and scores as high severity. The CVE text describes remote attacker impact, while the NVD CVSS vector indicates local access with user interaction is required; either way, the issue is security-re [truncated]

HIGH Debian CVE published 2017-02-15

CVE-2016-8682

CVE-2016-8682 describes a memory-safety flaw in GraphicsMagick 1.3.25: the ReadSCTImage function in coders/sct.c can read out of bounds when it processes a crafted SCT header. The published impact is denial of service, and NVD rates the issue High with a network attack vector, no privileges, and no user interaction. Public advisories and patch references were circulating in 2016, while the CVE record was [truncated]

HIGH Debian CVE published 2017-02-15

CVE-2015-8979

CVE-2015-8979 is a remotely triggerable memory-safety flaw in dcmtk’s storescp service that can crash the DICOM listener with a segmentation fault. NVD rates it HIGH because it is network-accessible, requires no authentication, and can be triggered by sending a long string to TCP port 4242.

HIGH Debian CVE published 2017-02-15

CVE-2017-5991

CVE-2017-5991 is a high-severity denial-of-service issue in Artifex MuPDF. The vulnerable code path is in pdf_run_xobject within pdf-op-run.c, where a NULL pointer dereference can occur during a Fitz painting operation. NVD rates the issue 7.5/HIGH with no confidentiality or integrity impact and availability impact only. The CVE record says versions 1.11 and later are not affected.

HIGH Debian CVE published 2017-02-09

CVE-2017-5847

CVE-2017-5847 is a remotely triggerable denial-of-service issue in GStreamer's ASF demuxer code. The vulnerable function, gst_asf_demux_process_ext_content_desc in gst/asfdemux/gstasfdemux.c, can read past the bounds of heap memory while processing extended content descriptors. NVD rates the issue as high availability impact with network access and no authentication or user interaction required (CVSS 3.1: [truncated]

MEDIUM Debian CVE published 2017-02-06

CVE-2016-9532

CVE-2016-9532 is a file-processing flaw in LibTIFF’s tiffcrop utility. A crafted TIFF file can trigger an integer overflow in writeBufferToSeparateStrips, leading to an out-of-bounds read and a denial-of-service condition. The NVD record lists the issue as medium severity and indicates user interaction is required to process the malicious file.

HIGH Debian CVE published 2017-01-30

CVE-2016-7798

CVE-2016-7798 is a high-severity weakness in the Ruby openssl gem and related Debian packages that ship it. According to NVD, when AES-GCM is used and the IV is set before the key, the library can reuse the same IV, which undermines the protection that GCM is meant to provide. The issue was publicly disclosed through mailing list discussion and a patch reference in 2016, and the CVE was published on 2017-01-30.

MEDIUM Debian CVE published 2017-01-30

CVE-2017-5612

CVE-2017-5612 is a cross-site scripting issue in WordPress’ admin posts list table. According to the NVD record, a crafted excerpt could inject arbitrary web script or HTML into the posts list view, and the vulnerable WordPress range extends through 4.7.1. WordPress 4.7.2 is the cited security release that addressed the issue.

MEDIUM Debian CVE published 2017-01-30

CVE-2017-5610

CVE-2017-5610 is a WordPress core information-disclosure issue in Press This. Before WordPress 4.7.2, the taxonomy-assignment user interface in wp-admin/includes/class-wp-press-this.php did not properly restrict visibility, allowing remote attackers to read terms they should not have been able to access. NVD rates the issue CVSS 5.3 (medium) with network access, no privileges, and no user interaction requ [truncated]

HIGH Debian CVE published 2017-01-27

CVE-2016-9453

CVE-2016-9453 is an out-of-bounds write flaw in LibTIFF's t2p_readwrite_pdf_image_tile function. The issue can lead to a crash and, according to the CVE description, may also permit arbitrary code execution when processing a crafted JPEG file with a TIFFTAG_JPEGTABLES value of length one. NVD rates the issue HIGH with CVSS 7.8 and lists a local, user-interactive attack vector.

HIGH Debian CVE published 2017-01-23

CVE-2015-8971

CVE-2015-8971 is a command-execution issue in Terminology 0.7.0. According to the NVD record, crafted escape sequences can alter the window title and then be written back to the terminal in a way that allows arbitrary command execution. The issue is rated HIGH by NVD and is tied to both the Terminology application and Debian Linux 8.0 package metadata in the CVE record.

MEDIUM Debian CVE published 2017-01-18

CVE-2016-7906

CVE-2016-7906 is a denial-of-service flaw in ImageMagick’s magick/attribute.c caused by a use-after-free. In practical terms, a crafted file can trigger a crash when it is processed by a vulnerable build. NVD assigns a medium severity score (CVSS 5.5) and records a vector that requires user interaction, so the main risk is availability loss in systems that accept untrusted image content.