CVE-2016-8808
published 2016-11-08CVE-2016-8808: For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the…
PriorityP343high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EXPLOIT
EPSS
1.60%
73.2th percentile
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70000d5 where a value passed from an user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nvidia | gpu_driver | >= 340 < 342.00 | 342.00 |
| nvidia | gpu_driver | >= 375 < 375.63 | 375.63 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Bugzilla
CVE-2016-5241 GraphicsMagick: SVG converting issues
bugzilla·2016-05-05·CVSS 5.5
CVE-2016-5241 [MEDIUM] CVE-2016-5241 GraphicsMagick: SVG converting issues
CVE-2016-5241 GraphicsMagick: SVG converting issues
Two vulnerabilities were found in GraphicsMagick, both resulting in DoS.
* Infinite loop caused by converting a circularly defined svg file.
Upstream patch:
http://hg.code.sf.net/p/graphicsmagick/code/rev/ddc999ec896c
* Arithmetic exception converting a svg file caused by a X%0 operation in
magick/render.c:3800
(long) (y-fill_pattern->tile_info.y) % fill_pattern->rows,
Upstream patch:
http://hg.code.sf.net/p/graphicsmagick/code/rev/8d175c4edfe7
References (containing reproducers):
http://seclists.org/oss-sec/2016/q2/180
Discussion:
Created GraphicsMagick tracking bugs for this issue:
Affects: fedora-all [bug 1333411]
Affects: epel-all [bug 1333412]
---
CVE assignment:
http://seclists.org/oss-sec/2016/q2/460
CVE-2016-5240
Bugzilla
CVE-2015-8808 GraphicsMagick: out-of-bound read in the parsing of GIF files
bugzilla·2016-02-08·CVSS 5.5
CVE-2015-8808 [MEDIUM] CVE-2015-8808 GraphicsMagick: out-of-bound read in the parsing of GIF files
CVE-2015-8808 GraphicsMagick: out-of-bound read in the parsing of GIF files
An out-of-bounds read flaw was found in the parsing of GIF files using GraphicsMagick.
$ ./gm identify overflow.gif
AddressSanitizer: heap-buffer-overflow
READ of size 1
SUMMARY: AddressSanitizer: heap-buffer-overflow coders/gif.c:276 DecodeImage
This issue is caused by the use of unintialized memory in DecodeImage and fortunately it was fixed here:
http://marc.info/?l=graphicsmagick-commit&m=142283721604323&w=2
Reported at:
http://seclists.org/oss-sec/2016/q1/288
Discussion:
Created GraphicsMagick tracking bugs for this issue:
Affects: fedora-all [bug 1305506]
Affects: epel-all [bug 1305507]
---
GraphicsMagick-1.3.23-1.fc22, gdl-0.9.5-10.fc22, octave-3.8.2-19.fc22, vdr-skinenigmang-0.1.2-27.fc22, vdr-
http://nvidia.custhelp.com/app/answers/detail/a_id/4247http://www.securityfocus.com/bid/93999https://support.lenovo.com/us/en/solutions/LEN-10822https://www.exploit-db.com/exploits/40666/http://nvidia.custhelp.com/app/answers/detail/a_id/4247http://www.securityfocus.com/bid/93999https://support.lenovo.com/us/en/solutions/LEN-10822https://www.exploit-db.com/exploits/40666/
2016-11-08
Published