CVE-2016-9956
published 2017-02-22CVE-2016-9956: The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.
PriorityP349high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
3.24%
87.0th percentile
The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | flightgear | < flightgear 1:2016.4.3+dfsg-1 (bookworm) | flightgear 1:2016.4.3+dfsg-1 (bookworm) |
| debian | flightgear | < flightgear 1:2016.4.4+dfsg-3 (bookworm) | flightgear 1:2016.4.4+dfsg-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| flightgear | flightgear | <= 2016.4.3 | — |
| flightgear | flightgear | <= 2017.2 | — |
| flightgear | flightgear | >= 0 < 1:2016.4.3+dfsg-1 | 1:2016.4.3+dfsg-1 |
| flightgear | flightgear | >= 0 < 1:2016.4.4+dfsg-3 | 1:2016.4.4+dfsg-3 |
| flightgear | flightgear | >= 0 < 1:2016.4.3+dfsg-1 | 1:2016.4.3+dfsg-1 |
| flightgear | flightgear | >= 0 < 1:2016.4.4+dfsg-3 | 1:2016.4.4+dfsg-3 |
| flightgear | flightgear | >= 0 < 1:2016.4.3+dfsg-1 | 1:2016.4.3+dfsg-1 |
| flightgear | flightgear | >= 0 < 1:2016.4.4+dfsg-3 | 1:2016.4.4+dfsg-3 |
| flightgear | flightgear | >= 0 < 1:2016.4.3+dfsg-1 | 1:2016.4.3+dfsg-1 |
| flightgear | flightgear | >= 0 < 1:2016.4.4+dfsg-3 | 1:2016.4.4+dfsg-3 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cm86-qqq5-r5v2: In FlightGear before 2017
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2017-8921 [HIGH] CWE-22 GHSA-cm86-qqq5-r5v2: In FlightGear before 2017
In FlightGear before 2017.2.1, the FGCommand interface allows overwriting any file the user has write access to, but not with arbitrary data: only with the contents of a FlightGear flightplan (XML). A resource such as a malicious third-party aircraft could exploit this to damage files belonging to the user. Both this issue and CVE-2016-9956 are directory traversal vulnerabilities in Autopilot/route_mgr.cxx - this one exists because of an incomplete fix for CVE-2016-9956.
GHSA
GHSA-gx42-hf7v-vhvg: The route manager in FlightGear before 2016
ghsa_unreviewed·2022-05-13
CVE-2016-9956 [HIGH] CWE-284 GHSA-gx42-hf7v-vhvg: The route manager in FlightGear before 2016
The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.
OSV
CVE-2017-8921: In FlightGear before 2017
osv·2017-05-12·CVSS 7.5
CVE-2017-8921 [HIGH] CVE-2017-8921: In FlightGear before 2017
In FlightGear before 2017.2.1, the FGCommand interface allows overwriting any file the user has write access to, but not with arbitrary data: only with the contents of a FlightGear flightplan (XML). A resource such as a malicious third-party aircraft could exploit this to damage files belonging to the user. Both this issue and CVE-2016-9956 are directory traversal vulnerabilities in Autopilot/route_mgr.cxx - this one exists because of an incomplete fix for CVE-2016-9956.
OSV
CVE-2016-9956: The route manager in FlightGear before 2016
osv·2017-02-22·CVSS 7.5
CVE-2016-9956 [HIGH] CVE-2016-9956: The route manager in FlightGear before 2016
The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.
Ubuntu
FlightGear vulnerability
vendor_ubuntu·2020-10-19
CVE-2016-9956 FlightGear vulnerability
Title: FlightGear vulnerability
Summary: FlightGear could be made to crash if it received specially crafted
input.
It was discovered that FlightGear could write arbitrary files if received a
special nasal script. A remote attacker could exploit this with a crafted
file to execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2017-8921: flightgear - In FlightGear before 2017.2.1, the FGCommand interface allows overwriting any fi...
vendor_debian·2017·CVSS 7.5
CVE-2017-8921 [HIGH] CVE-2017-8921: flightgear - In FlightGear before 2017.2.1, the FGCommand interface allows overwriting any fi...
In FlightGear before 2017.2.1, the FGCommand interface allows overwriting any file the user has write access to, but not with arbitrary data: only with the contents of a FlightGear flightplan (XML). A resource such as a malicious third-party aircraft could exploit this to damage files belonging to the user. Both this issue and CVE-2016-9956 are directory traversal vulnerabilities in Autopilot/route_mgr.cxx - this one exists because of an incomplete fix for CVE-2016-9956.
Scope: local
bookworm: resolved (fixed in 1:2016.4.4+dfsg-3)
bullseye: resolved (fixed in 1:2016.4.4+dfsg-3)
forky: resolved (fixed in 1:2016.4.4+dfsg-3)
sid: resolved (fixed in 1:2016.4.4+dfsg-3)
trixie: resolved (fixed in 1:2016.4.4+dfsg-3)
Debian
CVE-2016-9956: flightgear - The route manager in FlightGear before 2016.4.4 allows remote attackers to write...
vendor_debian·2016·CVSS 7.5
CVE-2016-9956 [HIGH] CVE-2016-9956: flightgear - The route manager in FlightGear before 2016.4.4 allows remote attackers to write...
The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.
Scope: local
bookworm: resolved (fixed in 1:2016.4.3+dfsg-1)
bullseye: resolved (fixed in 1:2016.4.3+dfsg-1)
forky: resolved (fixed in 1:2016.4.3+dfsg-1)
sid: resolved (fixed in 1:2016.4.3+dfsg-1)
trixie: resolved (fixed in 1:2016.4.3+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9956 FlightGear: Route manager allows overwrite of arbitrary files
bugzilla·2016-12-16·CVSS 7.5
CVE-2016-9956 [HIGH] CVE-2016-9956 FlightGear: Route manager allows overwrite of arbitrary files
CVE-2016-9956 FlightGear: Route manager allows overwrite of arbitrary files
The FlightGear project fixed a security issue, allowing arbitrary file
overwrites for files the user running FlightGear has write access to
and could be taken advantage to for other impact as arbitrary code
execution.
References:
http://seclists.org/oss-sec/2016/q4/674
Upstream patch:
https://sourceforge.net/p/flightgear/flightgear/ci/280cd523686fbdb175d50417266d2487a8ce67d2/
Discussion:
Created FlightGear tracking bugs for this issue:
Affects: fedora-all [bug 1405413]
---
Please, be aware that the fix for this issue seem to be incomplete:
http://seclists.org/oss-sec/2017/q2/255
---
Yes, that's right, updated packages for this new CVE have been built yesterday:
https://koji.fedoraproject.org/koji/buil
Bugzilla
CVE-2016-9956 FlightGear: Route manager allows overwrite of arbitrary files [fedora-all]
bugzilla·2016-12-16·CVSS 7.5
CVE-2016-9956 [HIGH] CVE-2016-9956 FlightGear: Route manager allows overwrite of arbitrary files [fedora-all]
CVE-2016-9956 FlightGear: Route manager allows overwrite of arbitrary files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
http://www.debian.org/security/2016/dsa-3742http://www.openwall.com/lists/oss-security/2016/12/14/11http://www.openwall.com/lists/oss-security/2016/12/15/10http://www.openwall.com/lists/oss-security/2016/12/16/5http://www.securityfocus.com/bid/94945https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZKAN7V6UOHSRFWO567XMN4O6WXTSL32/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DB3B5XBB2NL2O2U4WNYGH7ZL45Q4UHGG/https://sourceforge.net/p/flightgear/flightgear/ci/280cd523686fbdb175d50417266d2487a8ce67d2/https://sourceforge.net/projects/flightgear/files/release-2016.4/https://usn.ubuntu.com/4588-1/http://www.debian.org/security/2016/dsa-3742http://www.openwall.com/lists/oss-security/2016/12/14/11http://www.openwall.com/lists/oss-security/2016/12/15/10http://www.openwall.com/lists/oss-security/2016/12/16/5http://www.securityfocus.com/bid/94945https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZKAN7V6UOHSRFWO567XMN4O6WXTSL32/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DB3B5XBB2NL2O2U4WNYGH7ZL45Q4UHGG/https://sourceforge.net/p/flightgear/flightgear/ci/280cd523686fbdb175d50417266d2487a8ce67d2/https://sourceforge.net/projects/flightgear/files/release-2016.4/https://usn.ubuntu.com/4588-1/
2017-02-22
Published