CVE-2016-7948: Critical severity centos libxrandr vulnerability
Published Dec 13, 2016
·Updated
X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data.
Affected Software
3 affected components
X.Org libXrandr<=1.5.0
Fedoraproject Fedora=24
Fedoraproject Fedora=25
Remediation
Event History
Dec 13, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7948?
CVE-2016-7948 is considered to have a medium severity due to the potential for remote exploitation leading to out-of-bounds write operations.
2
How do I fix CVE-2016-7948?
To fix CVE-2016-7948, upgrade your X.org libXrandr to version 1.5.1 or later.
3
What types of systems are affected by CVE-2016-7948?
CVE-2016-7948 affects X.org libXrandr versions before 1.5.1 and specific Fedora distributions, including versions 24 and 25.
4
What is the impact of CVE-2016-7948?
The impact of CVE-2016-7948 includes potential application crashes or arbitrary code execution due to mishandling of reply data.
5
Is CVE-2016-7948 a local or remote vulnerability?
CVE-2016-7948 is a remote vulnerability that allows remote X servers to exploit the affected systems.