CVE-2016-6855: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 18.4% chance of exploitation in the next 30 days.
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only
- Fedoraproject Fedora: version 23 only; version 24 only
- Gnome Eye Of Gnome: version 3.16.5 only; version 3.17.1 only; version 3.17.2 only; version 3.17.3 only; version 3.17.90 only; version 3.17.91 only; …
- Opensuse Leap: version 42.1 only
- Opensuse Opensuse: version 13.2 only
Published 2016-09-07. Last modified 2026-06-17.