First published: Tue Dec 13 2016(Updated: )
The XRenderQueryFilters function in X.org libXrender before 0.9.10 allows remote X servers to trigger out-of-bounds write operations via vectors involving filter name lengths.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE LibXrender1 | <=0.9.9 | |
Fedora | =24 | |
Fedora | =25 |
https://cgit.freedesktop.org/xorg/lib/libXrender/commit/?id=8fad00b0b647ee662ce4737ca15be033b7a21714
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7950 is considered a high severity vulnerability due to its potential for out-of-bounds write operations.
To fix CVE-2016-7950, you should upgrade libXrender to version 0.9.10 or later.
CVE-2016-7950 affects systems running libXrender versions prior to 0.9.10 and specifically certain Fedora versions.
The impact of CVE-2016-7950 can include remote code execution due to out-of-bounds write vulnerabilities.
CVE-2016-7950 is classified as a remote vulnerability, allowing exploitation via remote X servers.