Buffer overflow in libxv - CVE-2016-5407

 

Buffer overflow in libxv - CVE-2016-5407

Published: December 13, 2016 / Updated: July 28, 2020


Vulnerability identifier: #VU32237
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5407
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifications in received data.


Affected software

libxv
Gentoo Linux
Slackware Linux
Ubuntu
Fedora
libxv (Alpine package)
libXv
libxv1 (Ubuntu package)

How to mitigate CVE-2016-5407

Install update from vendor's website.

libxv - update to 1.0.11
libxv (Alpine package) - addressed in versions 1.0.10-r1, 1.0.10-r2
libXv - addressed in versions 1.0.11-1.fc23, 1.0.11-1.fc24, 1.0.11-1.fc25
libxv1 (Ubuntu package) - update to 2:1.0.101ubuntu0.16.04.1~esm1

External References

Related Security Bulletins