CVE-2016-7952: Input Validation
Published Dec 13, 2016
·Updated
X.org libXtst before 1.2.3 allows remote X servers to cause a denial of service (infinite loop) via a reply in the (1) XRecordStartOfData, (2) XRecordEndOfData, or (3) XRecordClientDied category without a client sequence and with attached data.
Affected Software
3 affected components
Fedoraproject Fedora=24
Fedoraproject Fedora=25
X.Org libXtst<=1.2.2
Remediation
Event History
Dec 13, 2016
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7952?
CVE-2016-7952 has a moderate severity level as it can lead to a denial of service due to an infinite loop.
2
How do I fix CVE-2016-7952?
To fix CVE-2016-7952, upgrade the X.org libXtst package to version 1.2.3 or later.
3
What systems are affected by CVE-2016-7952?
CVE-2016-7952 affects Fedora versions 24 and 25 as well as X.org libXtst versions prior to 1.2.3.
4
What types of attacks exploit CVE-2016-7952?
CVE-2016-7952 can be exploited by remote X servers to trigger a denial of service.
5
Is CVE-2016-7952 limited to local network attacks?
No, CVE-2016-7952 can potentially be exploited over a network, allowing remote attackers to cause service interruptions.