First published: Wed Feb 22 2017(Updated: )
The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/flightgear | <1:2016.4.3+dfsg-1 | 1:2016.4.3+dfsg-1 |
ubuntu/flightgear | <3.4.0-3ubuntu1.1 | 3.4.0-3ubuntu1.1 |
debian/flightgear | 1:2020.3.6+dfsg-1 1:2020.3.16+dfsg-1 1:2020.3.18+dfsg-1.1 | |
Debian | =8.0 | |
Fedora | =24 | |
Fedora | =25 | |
Fipsasp Fipscms Light | <=2016.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9956 is considered a high severity vulnerability because it allows remote attackers to write to arbitrary files.
To fix CVE-2016-9956, upgrade FlightGear to version 2016.4.4 or later.
CVE-2016-9956 affects users of FlightGear versions prior to 2016.4.4.
CVE-2016-9956 allows exploitation through crafted Nasal scripts leading to arbitrary file write.
CVE-2016-9956 impacts various versions of Debian and Fedora that run vulnerable versions of FlightGear.