Buffer overflow in libxvmc - CVE-2016-7953
Published: December 13, 2016 / Updated: July 28, 2020
Vulnerability identifier: #VU32238
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-7953
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.
Affected software
libxvmc
Gentoo Linux
Slackware Linux
Fedora
libxvmc (Alpine package)
libXvMC
Gentoo Linux
Slackware Linux
Fedora
libxvmc (Alpine package)
libXvMC
How to mitigate CVE-2016-7953
Install update from vendor's website.
libxvmc - update to 1.0.10
libxvmc (Alpine package) - update to 1.0.8-r1
libXvMC - addressed in versions 1.0.10-1.fc23, 1.0.10-1.fc24, 1.0.10-1.fc25
libxvmc (Alpine package) - update to 1.0.8-r1
libXvMC - addressed in versions 1.0.10-1.fc23, 1.0.10-1.fc24, 1.0.10-1.fc25
External References
- http://www.openwall.com/lists/oss-security/2016/10/04/2
- http://www.openwall.com/lists/oss-security/2016/10/04/4
- http://www.securityfocus.com/bid/93371
- http://www.securitytracker.com/id/1036945
- https://cgit.freedesktop.org/xorg/lib/libXvMC/commit/?id=2cd95e7da8367cccdcdd5c9b160012d1dec5cbdb
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DLZ3CBE3LKTSHIQYM6RKZYJ5PJ5IGTYG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M4SI52ZOHOK6524DI2TOW4DX6HPKNFNB/
- https://lists.x.org/archives/xorg-announce/2016-October/002720.html
- https://security.gentoo.org/glsa/201704-03