CVE-2016-7946: High severity libxi vulnerability
Published Dec 13, 2016
·Updated
X.org libXi before 1.7.7 allows remote X servers to cause a denial of service (infinite loop) via vectors involving length fields.
Affected Software
3 affected components
X.Org libXi<=1.7.6
Fedoraproject Fedora=24
Fedoraproject Fedora=25
Remediation
Event History
Dec 13, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7946?
CVE-2016-7946 is considered a medium severity vulnerability as it can lead to denial of service due to an infinite loop.
2
How do I fix CVE-2016-7946?
To fix CVE-2016-7946, upgrade the libXi package to version 1.7.7 or later.
3
What systems are affected by CVE-2016-7946?
CVE-2016-7946 affects X.org libXi versions prior to 1.7.7 and Fedora versions 24 and 25.
4
Is CVE-2016-7946 remotely exploitable?
Yes, CVE-2016-7946 can be exploited by remote X servers to cause a denial of service.
5
What are the implications of CVE-2016-7946?
The implication of CVE-2016-7946 is that it allows an attacker to disrupt services by creating an infinite loop, potentially affecting system stability.