CVE-2016-10164
published 2017-02-01CVE-2016-10164: Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cause a…
PriorityP354critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
7.53%
93.8th percentile
Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via (1) the number of extensions or (2) their concatenated length in a crafted XPM file, which triggers a heap-based buffer overflow.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libxpm | < libxpm 1:3.5.12-1 (bookworm) | libxpm 1:3.5.12-1 (bookworm) |
| x.org | libxpm | <= 3.5.11 | — |
| x.org | libxpm | >= 0 < 1:3.5.12-1 | 1:3.5.12-1 |
| x.org | libxpm | >= 0 < 1:3.5.12-1 | 1:3.5.12-1 |
| x.org | libxpm | >= 0 < 1:3.5.12-1 | 1:3.5.12-1 |
| x.org | libxpm | >= 0 < 1:3.5.12-1 | 1:3.5.12-1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libXpm vulnerability
vendor_ubuntu·2017-02-01
CVE-2016-10164 libXpm vulnerability
Title: libXpm vulnerability
Summary: libXpm could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that libXpm incorrectly handled certain XPM files. If a
user or automated system were tricked into opening a specially crafted XPM
file, a remote attacker could use this issue to cause libXpm to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Red Hat
libXpm: Out-of-bounds write in XPM extension parsing
vendor_redhat·2016-12-12·CVSS 9.8
CVE-2016-10164 [CRITICAL] CWE-787 libXpm: Out-of-bounds write in XPM extension parsing
libXpm: Out-of-bounds write in XPM extension parsing
Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via (1) the number of extensions or (2) their concatenated length in a crafted XPM file, which triggers a heap-based buffer overflow.
An integer overflow flaw leading to a heap-based buffer overflow was found in libXpm. An attacker could use this flaw to crash an application using libXpm via a specially crafted XPM file.
Package: libXpm (Red Hat Enterprise Linux 5) - Will not fix
Package: libXpm (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2016-10164: libxpm - Multiple integer overflows in libXpm before 3.5.12, when a program requests pars...
vendor_debian·2016·CVSS 9.8
CVE-2016-10164 [CRITICAL] CVE-2016-10164: libxpm - Multiple integer overflows in libXpm before 3.5.12, when a program requests pars...
Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via (1) the number of extensions or (2) their concatenated length in a crafted XPM file, which triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1:3.5.12-1)
bullseye: resolved (fixed in 1:3.5.12-1)
forky: resolved (fixed in 1:3.5.12-1)
sid: resolved (fixed in 1:3.5.12-1)
trixie: resolved (fixed in 1:3.5.12-1)
GHSA
GHSA-fhfv-mh3h-f699: Multiple integer overflows in libXpm before 3
ghsa_unreviewed·2022-05-14
CVE-2016-10164 [CRITICAL] CWE-119 GHSA-fhfv-mh3h-f699: Multiple integer overflows in libXpm before 3
Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via (1) the number of extensions or (2) their concatenated length in a crafted XPM file, which triggers a heap-based buffer overflow.
OSV
CVE-2016-10164: Multiple integer overflows in libXpm before 3
osv·2017-02-01·CVSS 9.8
CVE-2016-10164 [CRITICAL] CVE-2016-10164: Multiple integer overflows in libXpm before 3
Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via (1) the number of extensions or (2) their concatenated length in a crafted XPM file, which triggers a heap-based buffer overflow.
No detection rules found.
No public exploits indexed.
arXiv
Using a Collated Cybersecurity Dataset for Machine Learning and Artificial Intelligence
arxiv_fulltext·2021-08-05
Using a Collated Cybersecurity Dataset for Machine Learning and Artificial Intelligence
Using a Collated Cybersecurity Dataset for Machine Learning and Artificial Intelligence
Erik Hemberg
MIT CSAIL
32 Vassar Street
Cambridge
United States of America
[email protected]
Una-May O'Reilly
MIT CSAIL
32 Vassar Street
Cambridge
United States of America
[email protected]
CAPEC
CVE
CWE
## Abstract
Artificial Intelligence (AI) and Machine Learning (ML) algorithms can support the span of indicator-level, e.g. anomaly detection, to behavioral level cyber security modeling and inference. This contribution is based on a dataset named which is amalgamated from public threat and vulnerability behavioral sources. We demonstrate how can support prediction of related threat techniques and attack patterns. We also discuss other AI and ML uses of to exploit its behavioral knowle
arXiv
Linking Threat Tactics, Techniques, and Patterns with Defensive Weaknesses, Vulnerabilities and Affected Platform Configurations for Cyber Hunting
arxiv_fulltext·2021-02-10·CVSS 8.8
CVE-2017-11882 [HIGH] Linking Threat Tactics, Techniques, and Patterns with Defensive Weaknesses, Vulnerabilities and Affected Platform Configurations for Cyber Hunting
Top 10 Most Exploited Vulnerabilities 2016-2019
(https://us-cert.cisa.gov/ncas/alerts/aa20-133a)
.83fcdec8a329824466f140a2e6cdfeec473a9ee2 .0
longtable[]@lllllll@
& CVSS Score & Number of Tactics & Number of Techniques &
Number of CAPECs & Number of CWEs & Number of CPEs
CVE-2017-11882 & 8.55 & 0 & 0 & 12 & 1 & 4
CVE-2017-0199 & 8.55 & 0 & 0 & 0 & 0 & 9
CVE-2017-5638 & 10.0 & 1 & 3 & 51 & 1 & 53
CVE-2012-0158 & 9.3 & 0 & 0 & 3 & 1 & 29
CVE-2019-0604 & 8.65 & 1 & 3 & 51 & 1 & 4
CVE-2017-0143 & 0.0 (not listed in BRON but NVD says high severity)
& 0 & 0 & 0 & 0 & 0
CVE-2018-4878 & 8.65 & 0 & 0 & 0 & 1 & 3
CVE-2017-8759 & 8.55 & 1 & 3 & 51 & 1 & 8
CVE-2015-1641 & 9.3 & 0 & 0 & 0 & 1 & 11
CVE-2018-7600 & 8.65 & 1 & 3 & 51 & 1 & 4
longtable
4 out of Top 10 Vulnerabilities share the follow
Bugzilla
CVE-2016-10164 libXpm: Out-of-bounds write in XPM extension parsing
bugzilla·2017-01-25·CVSS 9.8
CVE-2016-10164 [CRITICAL] CVE-2016-10164 libXpm: Out-of-bounds write in XPM extension parsing
CVE-2016-10164 libXpm: Out-of-bounds write in XPM extension parsing
An out of boundary write has been found in libXpm which can be exploited by an attacker through maliciously crafted XPM files.
The affected code is prone to two 32 bit integer overflows while parsing extensions: the amount of extensions and their concatenated length.
References:
http://seclists.org/oss-sec/2017/q1/167
Upstream patch:
https://cgit.freedesktop.org/xorg/lib/libXpm/commit/?id=d1167418f0fd02a27f617ec5afd6db053afbe185
Discussion:
Created libXpm tracking bugs for this issue:
Affects: fedora-24 [bug 1416442]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:1865 https://access.redhat.com/errata/RHSA-2017:1865
Bugzilla
CVE-2016-10164 libXpm: Out-of-bounds write in XPM extension parsing [fedora-24]
bugzilla·2017-01-25·CVSS 9.8
CVE-2016-10164 [CRITICAL] CVE-2016-10164 libXpm: Out-of-bounds write in XPM extension parsing [fedora-24]
CVE-2016-10164 libXpm: Out-of-bounds write in XPM extension parsing [fedora-24]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Di
http://www.debian.org/security/2017/dsa-3772http://www.openwall.com/lists/oss-security/2017/01/22/2http://www.openwall.com/lists/oss-security/2017/01/25/7http://www.securityfocus.com/bid/95785https://access.redhat.com/errata/RHSA-2017:1865https://cgit.freedesktop.org/xorg/lib/libXpm/commit/?id=d1167418f0fd02a27f617ec5afd6db053afbe185https://lists.freedesktop.org/archives/xorg/2016-December/058537.htmlhttps://security.gentoo.org/glsa/201701-72http://www.debian.org/security/2017/dsa-3772http://www.openwall.com/lists/oss-security/2017/01/22/2http://www.openwall.com/lists/oss-security/2017/01/25/7http://www.securityfocus.com/bid/95785https://access.redhat.com/errata/RHSA-2017:1865https://cgit.freedesktop.org/xorg/lib/libXpm/commit/?id=d1167418f0fd02a27f617ec5afd6db053afbe185https://lists.freedesktop.org/archives/xorg/2016-December/058537.htmlhttps://security.gentoo.org/glsa/201701-72
2017-02-01
Published