Out-of-bounds read in libxi - CVE-2016-7945
Published: December 13, 2016 / Updated: July 28, 2020
Vulnerability identifier: #VU32229
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-7945
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Multiple integer overflows in X.org libXi before 1.7.7 allow remote X servers to cause a denial of service (out-of-bounds memory access or infinite loop) via vectors involving length fields.
Affected software
libxi
libxi (Alpine package)
libXi
libxi6 (Ubuntu package)
Gentoo Linux
Slackware Linux
Ubuntu
Fedora
libxi (Alpine package)
libXi
libxi6 (Ubuntu package)
Gentoo Linux
Slackware Linux
Ubuntu
Fedora
How to mitigate CVE-2016-7945
Install update from vendor's website.
libxi - update to 1.7.7
libxi (Alpine package) - update to 1.7.4-r1
libXi - addressed in versions 1.7.7-1.fc23, 1.7.7-1.fc24, 1.7.7-1.fc25, 1.7.7-2.fc23, 1.7.8-2.fc23
libxi6 (Ubuntu package) - update to 2:1.7.61ubuntu0.1~esm1
libxi (Alpine package) - update to 1.7.4-r1
libXi - addressed in versions 1.7.7-1.fc23, 1.7.7-1.fc24, 1.7.7-1.fc25, 1.7.7-2.fc23, 1.7.8-2.fc23
libxi6 (Ubuntu package) - update to 2:1.7.61ubuntu0.1~esm1
External References
- http://www.openwall.com/lists/oss-security/2016/10/04/2
- http://www.openwall.com/lists/oss-security/2016/10/04/4
- http://www.securityfocus.com/bid/93364
- http://www.securitytracker.com/id/1036945
- https://cgit.freedesktop.org/xorg/lib/libXi/commit/?id=19a9cd607de73947fcfb104682f203ffe4e1f4e5
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C3NTWIWSQ575GREBVAOUQUIMDL5CDVGP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KVTZ2XLPKLASQUIQA2GMKKAUOQIUMM7I/
- https://lists.x.org/archives/xorg-announce/2016-October/002720.html
- https://security.gentoo.org/glsa/201704-03
Related Security Bulletins
- Out-of-bounds read in xorg.freedesktop libxi
- Out-of-bounds read in libxi (Alpine package)
- Gentoo update for X.Org
- Slackware Linux update for x11
- Ubuntu update for libxi
- Fedora 25 update for libXi
- Fedora 24 update for libXi
- Fedora 23 update for libXi
- Fedora 23 update for libXi
- Fedora 23 update for libXi