CVE-2016-9956

The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.
References
Link Resource
http://www.debian.org/security/2016/dsa-3742 Third Party Advisory
http://www.openwall.com/lists/oss-security/2016/12/14/11 Mailing List Patch Third Party Advisory
http://www.openwall.com/lists/oss-security/2016/12/15/10 Mailing List Patch Third Party Advisory
http://www.openwall.com/lists/oss-security/2016/12/16/5 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/94945 Third Party Advisory VDB Entry
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZKAN7V6UOHSRFWO567XMN4O6WXTSL32/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DB3B5XBB2NL2O2U4WNYGH7ZL45Q4UHGG/
https://sourceforge.net/p/flightgear/flightgear/ci/280cd523686fbdb175d50417266d2487a8ce67d2/ Issue Tracking Patch Third Party Advisory
https://sourceforge.net/projects/flightgear/files/release-2016.4/ Patch Release Notes Third Party Advisory
https://usn.ubuntu.com/4588-1/
http://www.debian.org/security/2016/dsa-3742 Third Party Advisory
http://www.openwall.com/lists/oss-security/2016/12/14/11 Mailing List Patch Third Party Advisory
http://www.openwall.com/lists/oss-security/2016/12/15/10 Mailing List Patch Third Party Advisory
http://www.openwall.com/lists/oss-security/2016/12/16/5 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/94945 Third Party Advisory VDB Entry
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZKAN7V6UOHSRFWO567XMN4O6WXTSL32/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DB3B5XBB2NL2O2U4WNYGH7ZL45Q4UHGG/
https://sourceforge.net/p/flightgear/flightgear/ci/280cd523686fbdb175d50417266d2487a8ce67d2/ Issue Tracking Patch Third Party Advisory
https://sourceforge.net/projects/flightgear/files/release-2016.4/ Patch Release Notes Third Party Advisory
https://usn.ubuntu.com/4588-1/
Configurations

Configuration 1 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:flightgear:flightgear:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:02

Type Values Removed Values Added
References () http://www.debian.org/security/2016/dsa-3742 - Third Party Advisory () http://www.debian.org/security/2016/dsa-3742 - Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2016/12/14/11 - Mailing List, Patch, Third Party Advisory () http://www.openwall.com/lists/oss-security/2016/12/14/11 - Mailing List, Patch, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2016/12/15/10 - Mailing List, Patch, Third Party Advisory () http://www.openwall.com/lists/oss-security/2016/12/15/10 - Mailing List, Patch, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2016/12/16/5 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2016/12/16/5 - Mailing List, Third Party Advisory
References () http://www.securityfocus.com/bid/94945 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/94945 - Third Party Advisory, VDB Entry
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZKAN7V6UOHSRFWO567XMN4O6WXTSL32/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZKAN7V6UOHSRFWO567XMN4O6WXTSL32/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DB3B5XBB2NL2O2U4WNYGH7ZL45Q4UHGG/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DB3B5XBB2NL2O2U4WNYGH7ZL45Q4UHGG/ -
References () https://sourceforge.net/p/flightgear/flightgear/ci/280cd523686fbdb175d50417266d2487a8ce67d2/ - Issue Tracking, Patch, Third Party Advisory () https://sourceforge.net/p/flightgear/flightgear/ci/280cd523686fbdb175d50417266d2487a8ce67d2/ - Issue Tracking, Patch, Third Party Advisory
References () https://sourceforge.net/projects/flightgear/files/release-2016.4/ - Patch, Release Notes, Third Party Advisory () https://sourceforge.net/projects/flightgear/files/release-2016.4/ - Patch, Release Notes, Third Party Advisory
References () https://usn.ubuntu.com/4588-1/ - () https://usn.ubuntu.com/4588-1/ -

07 Nov 2023, 02:37

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DB3B5XBB2NL2O2U4WNYGH7ZL45Q4UHGG/', 'name': 'FEDORA-2016-a1f774c3d7', 'tags': ['Third Party Advisory'], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BZKAN7V6UOHSRFWO567XMN4O6WXTSL32/', 'name': 'FEDORA-2016-01eba63bcc', 'tags': ['Third Party Advisory'], 'refsource': 'FEDORA'}
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BZKAN7V6UOHSRFWO567XMN4O6WXTSL32/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DB3B5XBB2NL2O2U4WNYGH7ZL45Q4UHGG/ -

Information

Published : 2017-02-22 16:59

Updated : 2024-11-21 03:02


NVD link : CVE-2016-9956

Mitre link : CVE-2016-9956

CVE.ORG link : CVE-2016-9956


JSON object : View

Products Affected

debian

  • debian_linux

flightgear

  • flightgear

fedoraproject

  • fedora
CWE
CWE-284

Improper Access Control