Out-of-bounds write in libxrandr - CVE-2016-7948
Published: December 13, 2016 / Updated: July 28, 2020
Vulnerability identifier: #VU32232
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-7948
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data.
Affected software
libxrandr
Gentoo Linux
Slackware Linux
Ubuntu
Fedora
libxrandr (Alpine package)
libxrandr2 (Ubuntu package)
libXrandr
Gentoo Linux
Slackware Linux
Ubuntu
Fedora
libxrandr (Alpine package)
libxrandr2 (Ubuntu package)
libXrandr
How to mitigate CVE-2016-7948
Install update from vendor's website.
libxrandr - update to 1.5.1
libxrandr (Alpine package) - update to 1.5.0-r1
libxrandr2 (Ubuntu package) - update to 2:1.5.01ubuntu0.1~esm1
libXrandr - addressed in versions 1.5.1-1.fc23, 1.5.1-1.fc24, 1.5.1-1.fc25
libxrandr (Alpine package) - update to 1.5.0-r1
libxrandr2 (Ubuntu package) - update to 2:1.5.01ubuntu0.1~esm1
libXrandr - addressed in versions 1.5.1-1.fc23, 1.5.1-1.fc24, 1.5.1-1.fc25
External References
- http://www.openwall.com/lists/oss-security/2016/10/04/2
- http://www.openwall.com/lists/oss-security/2016/10/04/4
- http://www.securityfocus.com/bid/93373
- http://www.securitytracker.com/id/1036945
- https://cgit.freedesktop.org/xorg/lib/libXrandr/commit/?id=a0df3e1c7728205e5c7650b2e6dce684139254a6
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/74FFOHWYIKQZTJLRJWDMJ4W3WYBELUUG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y7662OZWCSTLRPKS6R3E4Y4M26BSVAAM/
- https://lists.x.org/archives/xorg-announce/2016-October/002720.html
- https://security.gentoo.org/glsa/201704-03