CVE-2017-16611: Medium severity Debian Debian Linux vulnerability
In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libxfontto a version that resolves this vulnerability.Fixed in 1:2.0.4-1Fixed in 1:2.0.4-1+deb11u1Fixed in 1:2.0.6-1Fixed in 1:2.0.6-1+deb12u1Fixed in 1:2.0.6-1+deb13u1Fixed in 1:2.0.8-1 - Upgrade
Upgrade
libXfontto a version that resolves this vulnerability.Fixed in 1.5.4 - Upgrade
Upgrade
libXfont2to a version that resolves this vulnerability.Fixed in 2.0.3
Event History
Frequently Asked Questions
What is CVE-2017-16611?
CVE-2017-16611 is a vulnerability in libXfont before 1.5.4 and libXfont2 before 2.0.3 that allows a local attacker to open files on the system as root.
What is the severity of CVE-2017-16611?
The severity of CVE-2017-16611 is medium with a CVSS score of 5.5.
Which software versions are affected by CVE-2017-16611?
The affected software versions are Debian Debian Linux 8.0 and 9.0, and Canonical Ubuntu Linux 14.04, 16.04, 17.04, and 17.10.
How can a local attacker exploit CVE-2017-16611?
A local attacker can exploit CVE-2017-16611 by opening files on the system, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.
Is there a fix available for CVE-2017-16611?
Yes, a fix for CVE-2017-16611 is available. It is recommended to update to libXfont version 1.5.4 or libXfont2 version 2.0.3 or later.