Out-of-bounds write in libxrender - CVE-2016-7950
Published: December 13, 2016 / Updated: July 28, 2020
Vulnerability identifier: #VU32234
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-7950
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The XRenderQueryFilters function in X.org libXrender before 0.9.10 allows remote X servers to trigger out-of-bounds write operations via vectors involving filter name lengths.
Affected software
libxrender
Gentoo Linux
Slackware Linux
Ubuntu
Fedora
libxrender (Alpine package)
libXrender
libxrender1 (Ubuntu package)
Gentoo Linux
Slackware Linux
Ubuntu
Fedora
libxrender (Alpine package)
libXrender
libxrender1 (Ubuntu package)
How to mitigate CVE-2016-7950
Install update from vendor's website.
libxrender - update to 0.9.10
libxrender (Alpine package) - update to 0.9.8-r1
libXrender - addressed in versions 0.9.10-1.fc23, 0.9.10-1.fc24, 0.9.10-1.fc25
libxrender1 (Ubuntu package) - update to 1:0.9.90ubuntu1+esm1
libxrender (Alpine package) - update to 0.9.8-r1
libXrender - addressed in versions 0.9.10-1.fc23, 0.9.10-1.fc24, 0.9.10-1.fc25
libxrender1 (Ubuntu package) - update to 1:0.9.90ubuntu1+esm1
External References
- http://www.openwall.com/lists/oss-security/2016/10/04/2
- http://www.openwall.com/lists/oss-security/2016/10/04/4
- http://www.securityfocus.com/bid/93369
- http://www.securitytracker.com/id/1036945
- https://cgit.freedesktop.org/xorg/lib/libXrender/commit/?id=8fad00b0b647ee662ce4737ca15be033b7a21714
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7WCKZFMZ76APAVMIRCUKKHEB4GAS7ZUP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZHUT5YOSWVMBJNWZGUQNZRBFIZKRM4A6/
- https://lists.x.org/archives/xorg-announce/2016-October/002720.html
- https://security.gentoo.org/glsa/201704-03