Buffer overflow in libxv - CVE-2016-5407
Published: December 13, 2016 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifications in received data.
Affected software
Gentoo Linux
Slackware Linux
Ubuntu
Fedora
libxv (Alpine package)
libXv
libxv1 (Ubuntu package)
How to mitigate CVE-2016-5407
libxv (Alpine package) - addressed in versions 1.0.10-r1, 1.0.10-r2
libXv - addressed in versions 1.0.11-1.fc23, 1.0.11-1.fc24, 1.0.11-1.fc25
libxv1 (Ubuntu package) - update to 2:1.0.101ubuntu0.16.04.1~esm1
External References
- http://www.openwall.com/lists/oss-security/2016/10/04/2
- http://www.openwall.com/lists/oss-security/2016/10/04/4
- http://www.securityfocus.com/bid/93368
- http://www.securitytracker.com/id/1036945
- https://cgit.freedesktop.org/xorg/lib/libXv/commit/?id=d9da580b46a28ab497de2e94fdc7b9ff953dab17
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3IA7BLB4C3JOYVU6UASGUJQJKUF6TO7E/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AE2VJOFA3EZA566RERQB54TFY56FROZR/
- https://lists.x.org/archives/xorg-announce/2016-October/002720.html
- https://security.gentoo.org/glsa/201704-03