CVE-2017-16612
published 2017-12-01CVE-2017-16612: libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like…
PriorityP340high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
5.17%
91.5th percentile
libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack vector exists against the related code in cursor/xcursor.c in Wayland through 1.14.0.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxcursor | < libxcursor 1:1.1.14-3.1 (bookworm) | libxcursor 1:1.1.14-3.1 (bookworm) |
| debian | wayland | < libxcursor 1:1.1.14-3.1 (bookworm) | libxcursor 1:1.1.14-3.1 (bookworm) |
| wayland | wayland | >= 0 < 1.14.0-2 | 1.14.0-2 |
| wayland | wayland | >= 0 < 1.14.0-2 | 1.14.0-2 |
| wayland | wayland | >= 0 < 1.14.0-2 | 1.14.0-2 |
| wayland | wayland | >= 0 < 1.14.0-2 | 1.14.0-2 |
| x | libxcursor | <= 1.1.14 | — |
| x | libxcursor | >= 0 < 1:1.1.14-3.1 | 1:1.1.14-3.1 |
| x | libxcursor | >= 0 < 1:1.1.14-3.1 | 1:1.1.14-3.1 |
| x | libxcursor | >= 0 < 1:1.1.14-3.1 | 1:1.1.14-3.1 |
| x | libxcursor | >= 0 < 1:1.1.14-3.1 | 1:1.1.14-3.1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Wayland vulnerability
vendor_ubuntu·2018-04-09
CVE-2017-16612 Wayland vulnerability
Title: Wayland vulnerability
Summary: Wayland could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that the Wayland Xcursor support incorrectly handled
certain files. An attacker could use these issues to cause Wayland to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
libxcursor vulnerability
vendor_ubuntu·2017-11-29
CVE-2017-16612 libxcursor vulnerability
Title: libxcursor vulnerability
Summary: libxcursor could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that libxcursor incorrectly handled certain files. An
attacker could use these issues to cause libxcursor to crash, resulting in
a denial of service, or possibly execute arbitrary code.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
libXcursor: file.c: heap-based buffer overflow when reading/creating images
vendor_redhat·2017-11-25·CVSS 7.5
CVE-2017-16612 [HIGH] CWE-190 libXcursor: file.c: heap-based buffer overflow when reading/creating images
libXcursor: file.c: heap-based buffer overflow when reading/creating images
libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack vector exists against the related code in cursor/xcursor.c in Wayland through 1.14.0.
Statement: This issue affects the versions of libXcursor as shipped with Red Hat Enterprise Linux 5. Red Hat Enterprise Linux 5 is now in Extended Life Cycle phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
This issue affects the ve
Debian
CVE-2017-16612: libxcursor - libXcursor before 1.1.15 has various integer overflows that could lead to heap b...
vendor_debian·2017·CVSS 7.5
CVE-2017-16612 [HIGH] CVE-2017-16612: libxcursor - libXcursor before 1.1.15 has various integer overflows that could lead to heap b...
libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack vector exists against the related code in cursor/xcursor.c in Wayland through 1.14.0.
Scope: local
bookworm: resolved (fixed in 1:1.1.14-3.1)
bullseye: resolved (fixed in 1:1.1.14-3.1)
forky: resolved (fixed in 1:1.1.14-3.1)
sid: resolved (fixed in 1:1.1.14-3.1)
trixie: resolved (fixed in 1:1.1.14-3.1)
GHSA
GHSA-777r-cpw4-3m4v: libXcursor before 1
ghsa_unreviewed·2022-05-14
CVE-2017-16612 [HIGH] CWE-190 GHSA-777r-cpw4-3m4v: libXcursor before 1
libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack vector exists against the related code in cursor/xcursor.c in Wayland through 1.14.0.
OSV
CVE-2017-16612: libXcursor before 1
osv·2017-12-01·CVSS 7.5
CVE-2017-16612 [HIGH] CVE-2017-16612: libXcursor before 1
libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack vector exists against the related code in cursor/xcursor.c in Wayland through 1.14.0.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-16612 libXcursor: file.c: heap-based buffer overflow when reading/creating images [fedora-all]
bugzilla·2017-11-29·CVSS 7.5
CVE-2017-16612 [HIGH] CVE-2017-16612 libXcursor: file.c: heap-based buffer overflow when reading/creating images [fedora-all]
CVE-2017-16612 libXcursor: file.c: heap-based buffer overflow when reading/creating images [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
Bugzilla
CVE-2017-16612 libXcursor: file.c: heap-based buffer overflow when reading/creating images
bugzilla·2017-11-29·CVSS 7.5
CVE-2017-16612 [HIGH] CVE-2017-16612 libXcursor: file.c: heap-based buffer overflow when reading/creating images
CVE-2017-16612 libXcursor: file.c: heap-based buffer overflow when reading/creating images
libXcursor before version 1.1.15 is vulnerable to heap overflows when parsing malicious files. (CVE-2017-16612) An attacker could use local privileges or trick a user into parsing a malicious file in order to gain control of a system.
It is possible to trigger heap overflows due to an integer overflow while parsing images and a signedness issue while parsing comments.
References:
http://openwall.com/lists/oss-security/2017/11/28/6
https://cgit.freedesktop.org/xorg/lib/libXcursor/commit/?id=4794b5dd34688158fb51a2943032569d3780c4b8
Discussion:
Created libXcursor tracking bugs for this issue:
Affects: fedora-all [bug 1518479]
---
There are 2 distinct issues covered in by this CVE:
- a signedness
http://security.cucumberlinux.com/security/details.php?id=156http://www.openwall.com/lists/oss-security/2017/11/28/6http://www.ubuntu.com/usn/USN-3501-1https://bugzilla.suse.com/show_bug.cgi?id=1065386https://cgit.freedesktop.org/wayland/wayland/commit/?id=5d201df72f3d4f4cb8b8f75f980169b03507da38https://cgit.freedesktop.org/xorg/lib/libXcursor/commit/?id=4794b5dd34688158fb51a2943032569d3780c4b8https://lists.debian.org/debian-lts-announce/2017/12/msg00002.htmlhttps://lists.freedesktop.org/archives/wayland-devel/2017-November/035979.htmlhttps://marc.info/?l=freedesktop-xorg-announce&m=151188036018262&w=2https://security.gentoo.org/glsa/201801-04https://usn.ubuntu.com/3622-1/https://www.debian.org/security/2017/dsa-4059http://security.cucumberlinux.com/security/details.php?id=156http://www.openwall.com/lists/oss-security/2017/11/28/6http://www.ubuntu.com/usn/USN-3501-1https://bugzilla.suse.com/show_bug.cgi?id=1065386https://cgit.freedesktop.org/wayland/wayland/commit/?id=5d201df72f3d4f4cb8b8f75f980169b03507da38https://cgit.freedesktop.org/xorg/lib/libXcursor/commit/?id=4794b5dd34688158fb51a2943032569d3780c4b8https://lists.debian.org/debian-lts-announce/2017/12/msg00002.htmlhttps://lists.freedesktop.org/archives/wayland-devel/2017-November/035979.htmlhttps://marc.info/?l=freedesktop-xorg-announce&m=151188036018262&w=2https://security.gentoo.org/glsa/201801-04https://usn.ubuntu.com/3622-1/https://www.debian.org/security/2017/dsa-4059
2017-12-01
Published