CVE-2016-9958
published 2017-04-12CVE-2016-9958: game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
PriorityP340high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
2.33%
81.7th percentile
game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | game-music-emu | < game-music-emu 0.6.0-4 (bookworm) | game-music-emu 0.6.0-4 (bookworm) |
| game-music-emu_project | game-music-emu | <= 0.6.0 | — |
| game-music-emu_project | game-music-emu | >= 0 < 0.6.0-4 | 0.6.0-4 |
| game-music-emu_project | game-music-emu | >= 0 < 0.6.0-4 | 0.6.0-4 |
| game-music-emu_project | game-music-emu | >= 0 < 0.6.0-4 | 0.6.0-4 |
| game-music-emu_project | game-music-emu | >= 0 < 0.6.0-4 | 0.6.0-4 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| opensuse_project | leap | — | — |
| suse | linux_enterprise | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
| suse | linux_enterprise_workstation_extension | — | — |
| suse | suse_linux_enterprise_server | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2016-9958: game-music-emu - game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory...
vendor_debian·2016·CVSS 7.8
CVE-2016-9958 [HIGH] CVE-2016-9958: game-music-emu - game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory...
game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
Scope: local
bookworm: resolved (fixed in 0.6.0-4)
bullseye: resolved (fixed in 0.6.0-4)
forky: resolved (fixed in 0.6.0-4)
sid: resolved (fixed in 0.6.0-4)
trixie: resolved (fixed in 0.6.0-4)
GHSA
GHSA-jvrm-7h8w-chxm: game-music-emu before 0
ghsa_unreviewed·2022-05-14
CVE-2016-9958 [HIGH] CWE-119 GHSA-jvrm-7h8w-chxm: game-music-emu before 0
game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
OSV
CVE-2016-9958: game-music-emu before 0
osv·2017-04-12·CVSS 7.8
CVE-2016-9958 [HIGH] CVE-2016-9958: game-music-emu before 0
game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
No detection rules found.
Bugzilla
CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 game-music-emu: Multiple issues due to incorrect emulation of the SPC700 audio co-processor of SNES
bugzilla·2016-12-16·CVSS 7.8
CVE-2016-9957 [HIGH] CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 game-music-emu: Multiple issues due to incorrect emulation of the SPC700 audio co-processor of SNES
CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 game-music-emu: Multiple issues due to incorrect emulation of the SPC700 audio co-processor of SNES
Incorrect emulation of the SPC700 audio co-processor of the Super
Nintendo Entertainment System allows the execution of arbitrary code
if a malformed SPC music file is opened.
References:
http://scarybeastsecurity.blogspot.cz/2016/12/redux-compromising-linux-using-snes.html
http://seclists.org/oss-sec/2016/q4/682
CVE assignments:
http://seclists.org/oss-sec/2016/q4/692
Discussion:
Created game-music-emu tracking bugs for this issue:
Affects: fedora-all [bug 1405424]
Affects: epel-all [bug 1405425]
---
FYI:
Package "audacious-plugins" contains a previously undiscovered bundled game-music-emu, which also is affect
Bugzilla
CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 game-music-emu: Multiple issues due to incorrect emulation of the SPC700 audio co-processor of SNES [epel-all]
bugzilla·2016-12-16·CVSS 7.8
CVE-2016-9957 [HIGH] CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 game-music-emu: Multiple issues due to incorrect emulation of the SPC700 audio co-processor of SNES [epel-all]
CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 game-music-emu: Multiple issues due to incorrect emulation of the SPC700 audio co-processor of SNES [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed i
Bugzilla
CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 game-music-emu: Multiple issues due to incorrect emulation of the SPC700 audio co-processor of SNES [fedora-all]
bugzilla·2016-12-16·CVSS 7.8
CVE-2016-9957 [HIGH] CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 game-music-emu: Multiple issues due to incorrect emulation of the SPC700 audio co-processor of SNES [fedora-all]
CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 game-music-emu: Multiple issues due to incorrect emulation of the SPC700 audio co-processor of SNES [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in t
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00090.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-01/msg00005.htmlhttp://www.openwall.com/lists/oss-security/2016/12/15/11http://www.securityfocus.com/bid/95305https://bitbucket.org/mpyne/game-music-emu/wiki/Homehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6LKMKVYS7AVB2EXC463FUYN6C6FABHME/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7Z2OVERYM6NW3FGVGTJUNSL5ZNFSH2S/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GGHAQI5Q2XDSPGRRKPJJM3A73VWAFSFL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QHFKIFSFIDXOKFUKAH2MBNXDTY6DYBF6/https://scarybeastsecurity.blogspot.in/2016/12/redux-compromising-linux-using-snes.htmlhttps://security.gentoo.org/glsa/201707-02http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00090.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-01/msg00005.htmlhttp://www.openwall.com/lists/oss-security/2016/12/15/11http://www.securityfocus.com/bid/95305https://bitbucket.org/mpyne/game-music-emu/wiki/Homehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6LKMKVYS7AVB2EXC463FUYN6C6FABHME/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7Z2OVERYM6NW3FGVGTJUNSL5ZNFSH2S/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GGHAQI5Q2XDSPGRRKPJJM3A73VWAFSFL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QHFKIFSFIDXOKFUKAH2MBNXDTY6DYBF6/https://scarybeastsecurity.blogspot.in/2016/12/redux-compromising-linux-using-snes.htmlhttps://security.gentoo.org/glsa/201707-02
2017-04-12
Published