CVE-2016-9960
published 2017-06-06CVE-2016-9960: game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
PriorityP416medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.53%
41.2th percentile
game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | game-music-emu | < game-music-emu 0.6.0-4 (bookworm) | game-music-emu 0.6.0-4 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| game-music-emu_project | game-music-emu | <= 0.6.0 | — |
| game-music-emu_project | game-music-emu | >= 0 < 0.6.0-4 | 0.6.0-4 |
| game-music-emu_project | game-music-emu | >= 0 < 0.6.0-4 | 0.6.0-4 |
| game-music-emu_project | game-music-emu | >= 0 < 0.6.0-4 | 0.6.0-4 |
| game-music-emu_project | game-music-emu | >= 0 < 0.6.0-4 | 0.6.0-4 |
| novell | suse_linux_enterprise_desktop | — | — |
| novell | suse_linux_enterprise_server | — | — |
| novell | suse_linux_enterprise_software_development_kit | — | — |
| opensuse | leap | — | — |
| opensuse_project | leap | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h99v-mrwp-7gw9: game-music-emu before 0
ghsa_unreviewed·2022-05-14
CVE-2016-9960 [MEDIUM] CWE-369 GHSA-h99v-mrwp-7gw9: game-music-emu before 0
game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
OSV
CVE-2016-9960: game-music-emu before 0
osv·2017-06-06·CVSS 5.5
CVE-2016-9960 [MEDIUM] CVE-2016-9960: game-music-emu before 0
game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
Debian
CVE-2016-9960: game-music-emu - game-music-emu before 0.6.1 allows local users to cause a denial of service (div...
vendor_debian·2016·CVSS 5.5
CVE-2016-9960 [MEDIUM] CVE-2016-9960: game-music-emu - game-music-emu before 0.6.1 allows local users to cause a denial of service (div...
game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
Scope: local
bookworm: resolved (fixed in 0.6.0-4)
bullseye: resolved (fixed in 0.6.0-4)
forky: resolved (fixed in 0.6.0-4)
sid: resolved (fixed in 0.6.0-4)
trixie: resolved (fixed in 0.6.0-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 game-music-emu: Multiple issues due to incorrect emulation of the SPC700 audio co-processor of SNES
bugzilla·2016-12-16·CVSS 7.8
CVE-2016-9957 [HIGH] CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 game-music-emu: Multiple issues due to incorrect emulation of the SPC700 audio co-processor of SNES
CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 game-music-emu: Multiple issues due to incorrect emulation of the SPC700 audio co-processor of SNES
Incorrect emulation of the SPC700 audio co-processor of the Super
Nintendo Entertainment System allows the execution of arbitrary code
if a malformed SPC music file is opened.
References:
http://scarybeastsecurity.blogspot.cz/2016/12/redux-compromising-linux-using-snes.html
http://seclists.org/oss-sec/2016/q4/682
CVE assignments:
http://seclists.org/oss-sec/2016/q4/692
Discussion:
Created game-music-emu tracking bugs for this issue:
Affects: fedora-all [bug 1405424]
Affects: epel-all [bug 1405425]
---
FYI:
Package "audacious-plugins" contains a previously undiscovered bundled game-music-emu, which also is affect
Bugzilla
CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 game-music-emu: Multiple issues due to incorrect emulation of the SPC700 audio co-processor of SNES [epel-all]
bugzilla·2016-12-16·CVSS 7.8
CVE-2016-9957 [HIGH] CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 game-music-emu: Multiple issues due to incorrect emulation of the SPC700 audio co-processor of SNES [epel-all]
CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 game-music-emu: Multiple issues due to incorrect emulation of the SPC700 audio co-processor of SNES [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed i
Bugzilla
CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 game-music-emu: Multiple issues due to incorrect emulation of the SPC700 audio co-processor of SNES [fedora-all]
bugzilla·2016-12-16·CVSS 7.8
CVE-2016-9957 [HIGH] CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 game-music-emu: Multiple issues due to incorrect emulation of the SPC700 audio co-processor of SNES [fedora-all]
CVE-2016-9957 CVE-2016-9958 CVE-2016-9959 CVE-2016-9960 CVE-2016-9961 game-music-emu: Multiple issues due to incorrect emulation of the SPC700 audio co-processor of SNES [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in t
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00090.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-01/msg00005.htmlhttp://www.openwall.com/lists/oss-security/2016/12/15/11http://www.securityfocus.com/bid/95305https://bitbucket.org/mpyne/game-music-emu/wiki/Homehttps://bugzilla.redhat.com/show_bug.cgi?id=1405423https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6LKMKVYS7AVB2EXC463FUYN6C6FABHME/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7Z2OVERYM6NW3FGVGTJUNSL5ZNFSH2S/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GGHAQI5Q2XDSPGRRKPJJM3A73VWAFSFL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QHFKIFSFIDXOKFUKAH2MBNXDTY6DYBF6/https://scarybeastsecurity.blogspot.in/2016/12/redux-compromising-linux-using-snes.htmlhttps://security.gentoo.org/glsa/201707-02http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00090.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-01/msg00005.htmlhttp://www.openwall.com/lists/oss-security/2016/12/15/11http://www.securityfocus.com/bid/95305https://bitbucket.org/mpyne/game-music-emu/wiki/Homehttps://bugzilla.redhat.com/show_bug.cgi?id=1405423https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6LKMKVYS7AVB2EXC463FUYN6C6FABHME/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7Z2OVERYM6NW3FGVGTJUNSL5ZNFSH2S/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GGHAQI5Q2XDSPGRRKPJJM3A73VWAFSFL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QHFKIFSFIDXOKFUKAH2MBNXDTY6DYBF6/https://scarybeastsecurity.blogspot.in/2016/12/redux-compromising-linux-using-snes.htmlhttps://security.gentoo.org/glsa/201707-02
2017-06-06
Published