Oval Definition:oval:org.opensuse.security:def:20165684
Revision Date:2022-06-30Version:1
Title:CVE-2016-5684
Description:

An exploitable out-of-bounds write vulnerability exists in the XMP image handling functionality of the FreeImage library. A specially crafted XMP file can cause an arbitrary memory overwrite resulting in code execution. An attacker can provide a malicious image to trigger this vulnerability.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-5684
Mitre CVE-2016-5684
SUSE CVE-2016-5684
openSUSE-SU-2018:0329-1
Platform(s):openSUSE Leap 42.3
openSUSE Tumbleweed
Product(s):
Definition Synopsis
  • openSUSE Leap 42.3 is installed
  • AND Package Information
  • freeimage-3.17.0-5 is installed
  • AND freeimage is signed with openSUSE key
  • OR
  • freeimage-devel-3.17.0-5 is installed
  • AND freeimage-devel is signed with openSUSE key
  • OR
  • libfreeimage3-3.17.0-5 is installed
  • AND libfreeimage3 is signed with openSUSE key
  • OR
  • libfreeimageplus3-3.17.0-5 is installed
  • AND libfreeimageplus3 is signed with openSUSE key
  • Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • freeimage-devel-3.18.0-4.4 is installed
  • OR libfreeimage3-3.18.0-4.4 is installed
  • OR libfreeimageplus3-3.18.0-4.4 is installed
  • BACK