PT-2016-7442 · X.Org Foundation+3 · Libxrender+3
Tobias Stoeckmann
·
Publicado
2016-10-12
·
Atualizado
2022-05-23
·
CVE-2016-7949
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
libXrender versions prior to 0.9.10
Description
The issue involves multiple buffer overflows in the XvQueryAdaptors and XvQueryEncodings functions. These buffer overflows can be triggered by remote X servers via vectors involving length fields, allowing out-of-bounds write operations.
Recommendations
For libXrender versions prior to 0.9.10, update to version 0.9.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the XvQueryAdaptors and XvQueryEncodings functions until a patch is available.
Correção
RCE
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Ubuntu
Libxrender