CVE-2016-9957: Buffer Overflow
Incorrect emulation of the SPC700 audio co-processor of the Super Nintendo Entertainment System allows the execution of arbitrary code if a malformed SPC music file is opened.
References:
http://scarybeastsecurity.blogspot.cz/2016/12/redux-compromising-linux-using-snes.html http://seclists.org/oss-sec/2016/q4/682
CVE assignments:
http://seclists.org/oss-sec/2016/q4/692
Other sources
Stack-based buffer overflow in game-music-emu before 0.6.1.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9957?
CVE-2016-9957 has a high severity rating due to its potential to allow arbitrary code execution.
How do I fix CVE-2016-9957?
To fix CVE-2016-9957, update the affected software to the latest version that addresses this vulnerability.
Which software is affected by CVE-2016-9957?
CVE-2016-9957 affects specific versions of openSUSE and SUSE Linux software including Leap 42.1, Leap 42.2, and various versions of SUSE Linux Enterprise.
What type of attack can CVE-2016-9957 facilitate?
CVE-2016-9957 can facilitate attacks where an attacker can execute arbitrary code by opening a malformed SPC music file.
Is there a workaround for CVE-2016-9957?
The best workaround for CVE-2016-9957 is to avoid opening SPC music files in the affected software until it is updated.