CVE-2016-9888: Null Pointer Dereference
Published Dec 8, 2016
·Updated
An error within the "tardirectoryforfile()" function (gsf-infile-tar.c) in GNOME Structured File Library before 1.14.41 can be exploited to trigger a Null pointer dereference and subsequently cause a crash via a crafted TAR file.
Affected Software
1 affected component
Gnome libgsf<=1.14.40
Remediation
Event History
Dec 8, 2016
CVE Published
via MITRE·08:08 AM
Data Sourced
via MITRE·08:08 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9888?
CVE-2016-9888 is considered a high severity vulnerability due to its potential to cause crashes from null pointer dereferences.
2
How do I fix CVE-2016-9888?
To fix CVE-2016-9888, update the GNOME Structured File Library to version 1.14.41 or later.
3
Which software is affected by CVE-2016-9888?
CVE-2016-9888 affects the GNOME Structured File Library versions prior to 1.14.41.
4
What is the exploit method for CVE-2016-9888?
CVE-2016-9888 can be exploited by using a crafted TAR file that triggers a null pointer dereference.
5
What are the potential impacts of CVE-2016-9888?
The potential impacts of CVE-2016-9888 include application crashes and denial of service.