Out-of-bounds read in libxi - CVE-2016-7945

 

Out-of-bounds read in libxi - CVE-2016-7945

Published: December 13, 2016 / Updated: July 28, 2020


Vulnerability identifier: #VU32229
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-7945
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

Multiple integer overflows in X.org libXi before 1.7.7 allow remote X servers to cause a denial of service (out-of-bounds memory access or infinite loop) via vectors involving length fields.


Affected software

libxi
libxi (Alpine package)
libXi
libxi6 (Ubuntu package)
Gentoo Linux
Slackware Linux
Ubuntu
Fedora

How to mitigate CVE-2016-7945

Install update from vendor's website.

libxi - update to 1.7.7
libxi (Alpine package) - update to 1.7.4-r1
libXi - addressed in versions 1.7.7-1.fc23, 1.7.7-1.fc24, 1.7.7-1.fc25, 1.7.7-2.fc23, 1.7.8-2.fc23
libxi6 (Ubuntu package) - update to 2:1.7.61ubuntu0.1~esm1

External References

Related Security Bulletins