SB2016121368 - Integer overflow in xorg.freedesktop libxfixes



SB2016121368 - Integer overflow in xorg.freedesktop libxfixes

Published: December 13, 2016 Updated: July 28, 2020

Security Bulletin ID SB2016121368
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Integer overflow (CVE-ID: CVE-2016-7944)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Integer overflow in X.org libXfixes before 5.0.3 on 32-bit platforms might allow remote X servers to gain privileges via a length value of INT_MAX, which triggers the client to stop reading data and get out of sync.


Remediation

Install update from vendor's website.