Candidate: CVE-2016-9400 PublicDate: 2017-02-22 16:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9400 https://www.teeworlds.com/?page=news&id=12086 http://www.openwall.com/lists/oss-security/2016/11/16/8 Description: The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical memory locations and possibly execute arbitrary code via vectors involving snap handling. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=844546 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_teeworlds: upstream: https://github.com/teeworlds/teeworlds/commit/ff254722a2683867fcb3e67569ffd36226c4bc62 upstream_teeworlds: released (0.6.4+dfsg-1) precise_teeworlds: ignored (reached end-of-life) precise/esm_teeworlds: DNE (precise was needs-triage) trusty_teeworlds: ignored (reached end-of-life) trusty/esm_teeworlds: DNE (trusty was needed) vivid/stable-phone-overlay_teeworlds: DNE vivid/ubuntu-core_teeworlds: DNE xenial_teeworlds: ignored (end of standard support, was needed) yakkety_teeworlds: ignored (reached end-of-life) zesty_teeworlds: not-affected (0.6.4+dfsg-1) artful_teeworlds: not-affected (0.6.4+dfsg-1) bionic_teeworlds: not-affected (0.6.4+dfsg-1) cosmic_teeworlds: not-affected (0.6.4+dfsg-1) disco_teeworlds: not-affected (0.6.4+dfsg-1) eoan_teeworlds: not-affected (0.6.4+dfsg-1) focal_teeworlds: not-affected (0.6.4+dfsg-1) groovy_teeworlds: not-affected (0.6.4+dfsg-1) hirsute_teeworlds: not-affected (0.6.4+dfsg-1) impish_teeworlds: not-affected (0.6.4+dfsg-1) jammy_teeworlds: not-affected (0.6.4+dfsg-1) devel_teeworlds: not-affected (0.6.4+dfsg-1)