Permissions, Privileges, and Access Controls in libx11 - CVE-2016-7942
Published: December 13, 2016 / Updated: July 28, 2020
Vulnerability identifier: #VU32226
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-7942
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geometry, which triggers out-of-bounds read operations.
Affected software
libx11
Gentoo Linux
Slackware Linux
Fedora
libx11 (Alpine package)
libX11
IBM BladeCenter Advanced Management Module
Gentoo Linux
Slackware Linux
Fedora
libx11 (Alpine package)
libX11
IBM BladeCenter Advanced Management Module
How to mitigate CVE-2016-7942
Install update from vendor's website.
libx11 - update to 1.6.4
libx11 (Alpine package) - update to 1.6.2-r2
IBM BladeCenter Advanced Management Module - update to BPET68C-3.68C
libX11 - update to 1.6.4-1.fc25
libx11 (Alpine package) - update to 1.6.2-r2
IBM BladeCenter Advanced Management Module - update to BPET68C-3.68C
libX11 - update to 1.6.4-1.fc25
External References
- http://www.openwall.com/lists/oss-security/2016/10/04/2
- http://www.openwall.com/lists/oss-security/2016/10/04/4
- http://www.securityfocus.com/bid/93363
- http://www.securitytracker.com/id/1036945
- https://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=8ea762f94f4c942d898fdeb590a1630c83235c17
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GMCVDXMFPXR7QGMKDG22WPPJCXH2X3L7/
- https://lists.x.org/archives/xorg-announce/2016-October/002720.html
- https://security.gentoo.org/glsa/201704-03
- https://usn.ubuntu.com/3758-1/
- https://usn.ubuntu.com/3758-2/
Related Security Bulletins
- Permissions, Privileges, and Access Controls in xorg.freedesktop libx11
- Permissions, Privileges, and Access Controls in libx11 (Alpine package)
- Gentoo update for X.Org
- Slackware Linux update for x11
- Multiple vulnerabilities in IBM BladeCenter Advanced Management Module (AMM)
- Fedora 25 update for libX11