First published: Tue Dec 13 2016(Updated: )
X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Libxrandr | <=1.5.0 | |
Fedora | =24 | |
Fedora | =25 |
https://cgit.freedesktop.org/xorg/lib/libXrandr/commit/?id=a0df3e1c7728205e5c7650b2e6dce684139254a6
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7948 is considered to have a medium severity due to the potential for remote exploitation leading to out-of-bounds write operations.
To fix CVE-2016-7948, upgrade your X.org libXrandr to version 1.5.1 or later.
CVE-2016-7948 affects X.org libXrandr versions before 1.5.1 and specific Fedora distributions, including versions 24 and 25.
The impact of CVE-2016-7948 includes potential application crashes or arbitrary code execution due to mishandling of reply data.
CVE-2016-7948 is a remote vulnerability that allows remote X servers to exploit the affected systems.