CVE-2016-7950
published 2016-12-13CVE-2016-7950: The XRenderQueryFilters function in X.org libXrender before 0.9.10 allows remote X servers to trigger out-of-bounds write operations via vectors involving…
PriorityP345critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.72%
84.4th percentile
The XRenderQueryFilters function in X.org libXrender before 0.9.10 allows remote X servers to trigger out-of-bounds write operations via vectors involving filter name lengths.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libxrender | < libxrender 1:0.9.10-1 (bookworm) | libxrender 1:0.9.10-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| x.org | libxrender | <= 0.9.9 | — |
| x.org | libxrender | >= 0 < 1:0.9.10-1 | 1:0.9.10-1 |
| x.org | libxrender | >= 0 < 1:0.9.10-1 | 1:0.9.10-1 |
| x.org | libxrender | >= 0 < 1:0.9.10-1 | 1:0.9.10-1 |
| x.org | libxrender | >= 0 < 1:0.9.10-1 | 1:0.9.10-1 |
| x.org | libxrender | >= 0 < 1:0.9.9-0ubuntu1+esm1 | 1:0.9.9-0ubuntu1+esm1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libXrender vulnerabilities
vendor_ubuntu·2022-05-23·CVSS 9.8
CVE-2016-7950 [CRITICAL] libXrender vulnerabilities
Title: libXrender vulnerabilities
Summary: Several security issues were fixed in libXrender.
Tobias Stoeckmann discovered that libXrender incorrectly handled certain
responses. An attacker could possibly use this issue to cause a denial
of service, or possibly execute arbitrary code.
(CVE-2016-7949, CVE-2016-7950)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libXrender: Insufficient validation of server responses results out-of-bounds write in XRenderQueryFilters
vendor_redhat·2016-09-25·CVSS 9.8
CVE-2016-7950 [CRITICAL] libXrender: Insufficient validation of server responses results out-of-bounds write in XRenderQueryFilters
libXrender: Insufficient validation of server responses results out-of-bounds write in XRenderQueryFilters
The XRenderQueryFilters function in X.org libXrender before 0.9.10 allows remote X servers to trigger out-of-bounds write operations via vectors involving filter name lengths.
Package: libXrender (Red Hat Enterprise Linux 5) - Will not fix
Package: libXrender (Red Hat Enterprise Linux 6) - Will not fix
Package: libXrender (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-7950: libxrender - The XRenderQueryFilters function in X.org libXrender before 0.9.10 allows remote...
vendor_debian·2016·CVSS 9.8
CVE-2016-7950 [CRITICAL] CVE-2016-7950: libxrender - The XRenderQueryFilters function in X.org libXrender before 0.9.10 allows remote...
The XRenderQueryFilters function in X.org libXrender before 0.9.10 allows remote X servers to trigger out-of-bounds write operations via vectors involving filter name lengths.
Scope: local
bookworm: resolved (fixed in 1:0.9.10-1)
bullseye: resolved (fixed in 1:0.9.10-1)
forky: resolved (fixed in 1:0.9.10-1)
sid: resolved (fixed in 1:0.9.10-1)
trixie: resolved (fixed in 1:0.9.10-1)
OSV
libxrender vulnerabilities
osv·2022-05-23·CVSS 9.8
CVE-2016-7949 [CRITICAL] libxrender vulnerabilities
libxrender vulnerabilities
Tobias Stoeckmann discovered that libXrender incorrectly handled certain
responses. An attacker could possibly use this issue to cause a denial
of service, or possibly execute arbitrary code.
(CVE-2016-7949, CVE-2016-7950)
GHSA
GHSA-397q-46c2-4jwp: The XRenderQueryFilters function in X
ghsa_unreviewed·2022-05-17
CVE-2016-7950 [CRITICAL] CWE-787 GHSA-397q-46c2-4jwp: The XRenderQueryFilters function in X
The XRenderQueryFilters function in X.org libXrender before 0.9.10 allows remote X servers to trigger out-of-bounds write operations via vectors involving filter name lengths.
OSV
CVE-2016-7950: The XRenderQueryFilters function in X
osv·2016-12-13·CVSS 9.8
CVE-2016-7950 [CRITICAL] CVE-2016-7950: The XRenderQueryFilters function in X
The XRenderQueryFilters function in X.org libXrender before 0.9.10 allows remote X servers to trigger out-of-bounds write operations via vectors involving filter name lengths.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7950 libXrender: Insufficient validation of server responses results out-of-bounds write in XRenderQueryFilters
bugzilla·2016-10-05·CVSS 9.8
CVE-2016-7950 [CRITICAL] CVE-2016-7950 libXrender: Insufficient validation of server responses results out-of-bounds write in XRenderQueryFilters
CVE-2016-7950 libXrender: Insufficient validation of server responses results out-of-bounds write in XRenderQueryFilters
It was found that when receiving a response from the server protocol data is not validated sufficiently. The memory for filter names is reserved right after receiving the reply. After that, filters are iterated and each individual filter name is stored in that reserved memory. The individual name lengths are not checked for validity, which means that a malicious server can reserve less memory than it will write to during each iteration.
Upstream patch:
https://cgit.freedesktop.org/xorg/lib/libXrender/commit/?id=8fad00b0b647ee662ce4737ca15be033b7a21714
External References:
https://lists.x.org/archives/xorg-announce/2016-October/002720.html
CVE assignment:
http://se
Bugzilla
CVE-2016-7949 CVE-2016-7950 libXrender: various flaws [fedora-all]
bugzilla·2016-10-05·CVSS 9.8
CVE-2016-7949 [CRITICAL] CVE-2016-7949 CVE-2016-7950 libXrender: various flaws [fedora-all]
CVE-2016-7949 CVE-2016-7950 libXrender: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whi
http://www.openwall.com/lists/oss-security/2016/10/04/2http://www.openwall.com/lists/oss-security/2016/10/04/4http://www.securityfocus.com/bid/93369http://www.securitytracker.com/id/1036945https://cgit.freedesktop.org/xorg/lib/libXrender/commit/?id=8fad00b0b647ee662ce4737ca15be033b7a21714https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WCKZFMZ76APAVMIRCUKKHEB4GAS7ZUP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZHUT5YOSWVMBJNWZGUQNZRBFIZKRM4A6/https://lists.x.org/archives/xorg-announce/2016-October/002720.htmlhttps://security.gentoo.org/glsa/201704-03http://www.openwall.com/lists/oss-security/2016/10/04/2http://www.openwall.com/lists/oss-security/2016/10/04/4http://www.securityfocus.com/bid/93369http://www.securitytracker.com/id/1036945https://cgit.freedesktop.org/xorg/lib/libXrender/commit/?id=8fad00b0b647ee662ce4737ca15be033b7a21714https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WCKZFMZ76APAVMIRCUKKHEB4GAS7ZUP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZHUT5YOSWVMBJNWZGUQNZRBFIZKRM4A6/https://lists.x.org/archives/xorg-announce/2016-October/002720.htmlhttps://security.gentoo.org/glsa/201704-03
2016-12-13
Published