Incorrect emulation of the SPC700 audio co-processor of the Super Nintendo Entertainment System allows the execution of arbitrary code if a malformed SPC music file is opened. References: http://scarybeastsecurity.blogspot.cz/2016/12/redux-compromising-linux-using-snes.html http://seclists.org/oss-sec/2016/q4/682 CVE assignments: http://seclists.org/oss-sec/2016/q4/692
Created game-music-emu tracking bugs for this issue: Affects: fedora-all [bug 1405424] Affects: epel-all [bug 1405425]
FYI: Package "audacious-plugins" contains a previously undiscovered bundled game-music-emu, which also is affected by this bug. "Provides: bundled(game-music-emu)" has been added. Fixed in Audacious 3.8.2 release for Fedora 25 and Rawhide, and a patch added to Audacious 3.7.2 for Fedora 24.
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.