CVE-2016-7947: Integer Overflow
Published Dec 13, 2016
·Updated
Multiple integer overflows in X.org libXrandr before 1.5.1 allow remote X servers to trigger out-of-bounds write operations via a crafted response.
Affected Software
3 affected components
Fedoraproject Fedora=24
Fedoraproject Fedora=25
X.Org libXrandr<=1.5.0
Remediation
Event History
Dec 13, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7947?
CVE-2016-7947 has a severity rating that indicates a significant risk due to potential remote code execution.
2
How do I fix CVE-2016-7947?
To fix CVE-2016-7947, upgrade X.org libXrandr to version 1.5.1 or later.
3
Which software is affected by CVE-2016-7947?
CVE-2016-7947 affects X.org libXrandr versions up to and including 1.5.0, as well as Fedora versions 24 and 25.
4
How does CVE-2016-7947 pose a risk?
CVE-2016-7947 poses a risk by allowing remote X servers to perform out-of-bounds write operations through crafted responses.
5
Who should be concerned about CVE-2016-7947?
Users and administrators of systems running affected versions of Fedora and X.org libXrandr should be concerned about CVE-2016-7947.