Improper access control in libxi - CVE-2016-7946
Published: December 13, 2016 / Updated: July 28, 2020
Vulnerability identifier: #VU32230
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-7946
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
X.org libXi before 1.7.7 allows remote X servers to cause a denial of service (infinite loop) via vectors involving length fields.
Affected software
libxi
libxi (Alpine package)
libXi
libxi6 (Ubuntu package)
Gentoo Linux
Slackware Linux
Ubuntu
Fedora
libxi (Alpine package)
libXi
libxi6 (Ubuntu package)
Gentoo Linux
Slackware Linux
Ubuntu
Fedora
How to mitigate CVE-2016-7946
Install update from vendor's website.
libxi - update to 1.7.7
libxi (Alpine package) - update to 1.7.4-r1
libXi - addressed in versions 1.7.7-1.fc23, 1.7.7-1.fc24, 1.7.7-1.fc25, 1.7.7-2.fc23, 1.7.8-2.fc23
libxi6 (Ubuntu package) - update to 2:1.7.61ubuntu0.1~esm1
libxi (Alpine package) - update to 1.7.4-r1
libXi - addressed in versions 1.7.7-1.fc23, 1.7.7-1.fc24, 1.7.7-1.fc25, 1.7.7-2.fc23, 1.7.8-2.fc23
libxi6 (Ubuntu package) - update to 2:1.7.61ubuntu0.1~esm1
External References
- http://www.openwall.com/lists/oss-security/2016/10/04/2
- http://www.openwall.com/lists/oss-security/2016/10/04/4
- http://www.securityfocus.com/bid/93374
- http://www.securitytracker.com/id/1036945
- https://cgit.freedesktop.org/xorg/lib/libXi/commit/?id=19a9cd607de73947fcfb104682f203ffe4e1f4e5
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C3NTWIWSQ575GREBVAOUQUIMDL5CDVGP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KVTZ2XLPKLASQUIQA2GMKKAUOQIUMM7I/
- https://lists.x.org/archives/xorg-announce/2016-October/002720.html
- https://security.gentoo.org/glsa/201704-03
Related Security Bulletins
- Improper access control in xorg.freedesktop libxi
- Improper access control in libxi (Alpine package)
- Gentoo update for X.Org
- Slackware Linux update for x11
- Ubuntu update for libxi
- Fedora 25 update for libXi
- Fedora 24 update for libXi
- Fedora 23 update for libXi
- Fedora 23 update for libXi
- Fedora 23 update for libXi