Out-of-Bounds Write Vulnerability in X.org libXrender Affects Multiple Linux Distributions
CVE-2016-7950

9.8CRITICAL

Key Information:

Vendor

X.org

Vendor
CVE Published:
13 December 2016

What is CVE-2016-7950?

The XRenderQueryFilters function within X.org's libXrender library prior to version 0.9.10 is susceptible to manipulation by remote X servers, enabling attackers to initiate out-of-bounds write operations. This vulnerability arises from improper handling of filter name lengths, potentially allowing the exploitation of memory corruption and leading to unintended code execution. Various Linux distributions that utilize this library are at risk, emphasizing the need for timely updates and system patches.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.