Integer overflow in libxfixes - CVE-2016-7944

 

Integer overflow in libxfixes - CVE-2016-7944

Published: December 13, 2016 / Updated: July 28, 2020


Vulnerability identifier: #VU32228
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-7944
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Integer overflow in X.org libXfixes before 5.0.3 on 32-bit platforms might allow remote X servers to gain privileges via a length value of INT_MAX, which triggers the client to stop reading data and get out of sync.


Affected software

libxfixes
Gentoo Linux
Slackware Linux
Ubuntu
Fedora
libxfixes (Alpine package)
libXfixes
libxfixes3 (Ubuntu package)

How to mitigate CVE-2016-7944

Install update from vendor's website.

libxfixes - update to 5.0.3
libxfixes (Alpine package) - addressed in versions 5.0.1-r1, 5.0.1-r2
libXfixes - addressed in versions 5.0.3-1.fc23, 5.0.3-1.fc24, 5.0.3-1.fc25
libxfixes3 (Ubuntu package) - update to 1:5.0.12ubuntu0.1~esm1

External References

Related Security Bulletins