CVE-2016-5407: Buffer Overflow
Published Dec 13, 2016
·Updated
The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifications in received data.
Affected Software
3 affected components
X.Org libXv<=1.0.10
Fedoraproject Fedora=24
Fedoraproject Fedora=25
Remediation
Event History
Dec 13, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5407?
CVE-2016-5407 is considered a high severity vulnerability due to its potential for remote exploitation leading to out-of-bounds memory access.
2
How do I fix CVE-2016-5407?
To fix CVE-2016-5407, upgrade X.org libXv to version 1.0.11 or later.
3
What versions of libXv are affected by CVE-2016-5407?
CVE-2016-5407 affects X.org libXv versions prior to 1.0.11.
4
Can CVE-2016-5407 be exploited remotely?
Yes, CVE-2016-5407 can be exploited by remote X servers triggering out-of-bounds memory access operations.
5
Which operating systems are impacted by CVE-2016-5407?
CVE-2016-5407 affects Fedora versions 24 and 25 that include vulnerable versions of libXv.