First published: Tue Dec 13 2016(Updated: )
X.org libXi before 1.7.7 allows remote X servers to cause a denial of service (infinite loop) via vectors involving length fields.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
X.org libXi | <=1.7.6 | |
Fedora | =24 | |
Fedora | =25 |
https://cgit.freedesktop.org/xorg/lib/libXi/commit/?id=19a9cd607de73947fcfb104682f203ffe4e1f4e5
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7946 is considered a medium severity vulnerability as it can lead to denial of service due to an infinite loop.
To fix CVE-2016-7946, upgrade the libXi package to version 1.7.7 or later.
CVE-2016-7946 affects X.org libXi versions prior to 1.7.7 and Fedora versions 24 and 25.
Yes, CVE-2016-7946 can be exploited by remote X servers to cause a denial of service.
The implication of CVE-2016-7946 is that it allows an attacker to disrupt services by creating an infinite loop, potentially affecting system stability.