CVE-2016-7953
published 2016-12-13CVE-2016-7953: Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.
PriorityP346critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.32%
87.2th percentile
Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libxvmc | < libxvmc 2:1.0.10-1 (bookworm) | libxvmc 2:1.0.10-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| x.org | libxvmc | <= 1.0.9 | — |
| x.org | libxvmc | >= 0 < 2:1.0.10-1 | 2:1.0.10-1 |
| x.org | libxvmc | >= 0 < 2:1.0.10-1 | 2:1.0.10-1 |
| x.org | libxvmc | >= 0 < 2:1.0.10-1 | 2:1.0.10-1 |
| x.org | libxvmc | >= 0 < 2:1.0.10-1 | 2:1.0.10-1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libXvMC: Insufficient validation of server responses results in buffer underflow
vendor_redhat·2016-09-25·CVSS 9.8
CVE-2016-7953 [CRITICAL] libXvMC: Insufficient validation of server responses results in buffer underflow
libXvMC: Insufficient validation of server responses results in buffer underflow
Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.
Package: libXvMC (Red Hat Enterprise Linux 5) - Will not fix
Package: libXvMC (Red Hat Enterprise Linux 6) - Will not fix
Package: libXvMC (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-7953: libxvmc - Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have ...
vendor_debian·2016·CVSS 9.8
CVE-2016-7953 [CRITICAL] CVE-2016-7953: libxvmc - Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have ...
Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.
Scope: local
bookworm: resolved (fixed in 2:1.0.10-1)
bullseye: resolved (fixed in 2:1.0.10-1)
forky: resolved (fixed in 2:1.0.10-1)
sid: resolved (fixed in 2:1.0.10-1)
trixie: resolved (fixed in 2:1.0.10-1)
GHSA
GHSA-w6wp-2rmw-f38w: Buffer underflow in X
ghsa_unreviewed·2022-05-17
CVE-2016-7953 [CRITICAL] CWE-119 GHSA-w6wp-2rmw-f38w: Buffer underflow in X
Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.
OSV
CVE-2016-7953: Buffer underflow in X
osv·2016-12-13·CVSS 9.8
CVE-2016-7953 [CRITICAL] CVE-2016-7953: Buffer underflow in X
Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7953 libXvMC: Insufficient validation of server responses results in buffer underflow
bugzilla·2016-10-05·CVSS 9.8
CVE-2016-7953 [CRITICAL] CVE-2016-7953 libXvMC: Insufficient validation of server responses results in buffer underflow
CVE-2016-7953 libXvMC: Insufficient validation of server responses results in buffer underflow
It was found that when receiving a response from the server protocol data is not validated sufficiently. If an empty string is received from an x-server, the buffer might underrun by accessing "rep.nameLen - 1" unconditionally, which could end up being -1.
Upstream patch:
https://cgit.freedesktop.org/xorg/lib/libXvMC/commit/?id=2cd95e7da8367cccdcdd5c9b160012d1dec5cbdb
External References:
https://lists.x.org/archives/xorg-announce/2016-October/002720.html
CVE assignment:
http://seclists.org/oss-sec/2016/q4/17
Discussion:
Created libXvMC tracking bugs for this issue:
Affects: fedora-all [bug 1381934]
Bugzilla
CVE-2016-7953 libXvMC: Insufficient validation of server responses results in buffer underflow [fedora-all]
bugzilla·2016-10-05·CVSS 9.8
CVE-2016-7953 [CRITICAL] CVE-2016-7953 libXvMC: Insufficient validation of server responses results in buffer underflow [fedora-all]
CVE-2016-7953 libXvMC: Insufficient validation of server responses results in buffer underflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
http://www.openwall.com/lists/oss-security/2016/10/04/2http://www.openwall.com/lists/oss-security/2016/10/04/4http://www.securityfocus.com/bid/93371http://www.securitytracker.com/id/1036945https://cgit.freedesktop.org/xorg/lib/libXvMC/commit/?id=2cd95e7da8367cccdcdd5c9b160012d1dec5cbdbhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DLZ3CBE3LKTSHIQYM6RKZYJ5PJ5IGTYG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M4SI52ZOHOK6524DI2TOW4DX6HPKNFNB/https://lists.x.org/archives/xorg-announce/2016-October/002720.htmlhttps://security.gentoo.org/glsa/201704-03http://www.openwall.com/lists/oss-security/2016/10/04/2http://www.openwall.com/lists/oss-security/2016/10/04/4http://www.securityfocus.com/bid/93371http://www.securitytracker.com/id/1036945https://cgit.freedesktop.org/xorg/lib/libXvMC/commit/?id=2cd95e7da8367cccdcdd5c9b160012d1dec5cbdbhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DLZ3CBE3LKTSHIQYM6RKZYJ5PJ5IGTYG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M4SI52ZOHOK6524DI2TOW4DX6HPKNFNB/https://lists.x.org/archives/xorg-announce/2016-October/002720.htmlhttps://security.gentoo.org/glsa/201704-03
2016-12-13
Published