CVE-2016-5407
published 2016-12-13CVE-2016-5407: The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access…
PriorityP350critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.53%
90.5th percentile
The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifications in received data.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libxv | < libxv 2:1.0.11-1 (bookworm) | libxv 2:1.0.11-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| x.org | libxv | <= 1.0.10 | — |
| x.org | libxv | >= 0 < 2:1.0.11-1 | 2:1.0.11-1 |
| x.org | libxv | >= 0 < 2:1.0.11-1 | 2:1.0.11-1 |
| x.org | libxv | >= 0 < 2:1.0.11-1 | 2:1.0.11-1 |
| x.org | libxv | >= 0 < 2:1.0.11-1 | 2:1.0.11-1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cwhm-4g62-g8f6: The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X
ghsa_unreviewed·2022-05-17
CVE-2016-5407 [CRITICAL] CWE-119 GHSA-cwhm-4g62-g8f6: The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X
The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifications in received data.
OSV
CVE-2016-5407: The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X
osv·2016-12-13·CVSS 9.8
CVE-2016-5407 [CRITICAL] CVE-2016-5407: The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X
The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifications in received data.
Ubuntu
libXv vulnerability
vendor_ubuntu·2022-05-26
CVE-2016-5407 libXv vulnerability
Title: libXv vulnerability
Summary: libXv could be made to crash or run programs if it received specially
crafted input.
It was discovered that libXv incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial
of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libXv: Insufficient validation of server responses results in out-of bounds accesses
vendor_redhat·2016-09-25·CVSS 9.8
CVE-2016-5407 [CRITICAL] libXv: Insufficient validation of server responses results in out-of bounds accesses
libXv: Insufficient validation of server responses results in out-of bounds accesses
The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifications in received data.
Package: libXv (Red Hat Enterprise Linux 5) - Will not fix
Package: libXv (Red Hat Enterprise Linux 6) - Will not fix
Package: libXv (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-5407: libxv - The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before...
vendor_debian·2016·CVSS 9.8
CVE-2016-5407 [CRITICAL] CVE-2016-5407: libxv - The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before...
The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifications in received data.
Scope: local
bookworm: resolved (fixed in 2:1.0.11-1)
bullseye: resolved (fixed in 2:1.0.11-1)
forky: resolved (fixed in 2:1.0.11-1)
sid: resolved (fixed in 2:1.0.11-1)
trixie: resolved (fixed in 2:1.0.11-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-5407 libXv: Insufficient validation of server responses results in out-of bounds accesses [fedora-all]
bugzilla·2016-10-05·CVSS 9.8
CVE-2016-5407 [CRITICAL] CVE-2016-5407 libXv: Insufficient validation of server responses results in out-of bounds accesses [fedora-all]
CVE-2016-5407 libXv: Insufficient validation of server responses results in out-of bounds accesses [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2016-5407 libXv: Insufficient validation of server responses results in out-of bounds accesses
bugzilla·2016-10-05·CVSS 9.8
CVE-2016-5407 [CRITICAL] CVE-2016-5407 libXv: Insufficient validation of server responses results in out-of bounds accesses
CVE-2016-5407 libXv: Insufficient validation of server responses results in out-of bounds accesses
It was found that when receiving a response from the server protocol data is not validated sufficiently. The Xv query functions for adaptors and encodings suffer from out of boundary accesses if a hostile X server sends a maliciously crafted response.
Upstream patch:
https://cgit.freedesktop.org/xorg/lib/libXv/commit/?id=d9da580b46a28ab497de2e94fdc7b9ff953dab17
External References:
https://lists.x.org/archives/xorg-announce/2016-October/002720.html
CVE assignment:
http://seclists.org/oss-sec/2016/q4/17
Discussion:
Created libXv tracking bugs for this issue:
Affects: fedora-all [bug 1381932]
---
Analysis:
This issue stem from the client libraries trusting the server to send correc
http://www.openwall.com/lists/oss-security/2016/10/04/2http://www.openwall.com/lists/oss-security/2016/10/04/4http://www.securityfocus.com/bid/93368http://www.securitytracker.com/id/1036945https://cgit.freedesktop.org/xorg/lib/libXv/commit/?id=d9da580b46a28ab497de2e94fdc7b9ff953dab17https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3IA7BLB4C3JOYVU6UASGUJQJKUF6TO7E/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AE2VJOFA3EZA566RERQB54TFY56FROZR/https://lists.x.org/archives/xorg-announce/2016-October/002720.htmlhttps://security.gentoo.org/glsa/201704-03http://www.openwall.com/lists/oss-security/2016/10/04/2http://www.openwall.com/lists/oss-security/2016/10/04/4http://www.securityfocus.com/bid/93368http://www.securitytracker.com/id/1036945https://cgit.freedesktop.org/xorg/lib/libXv/commit/?id=d9da580b46a28ab497de2e94fdc7b9ff953dab17https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3IA7BLB4C3JOYVU6UASGUJQJKUF6TO7E/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AE2VJOFA3EZA566RERQB54TFY56FROZR/https://lists.x.org/archives/xorg-announce/2016-October/002720.htmlhttps://security.gentoo.org/glsa/201704-03
2016-12-13
Published