4.9
CVSSv2

CVE-2017-16611

Published: 01/12/2017 Updated: 20/02/2022
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

In libXfont prior to 1.5.4 and libXfont2 prior to 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

debian debian linux 9.0

canonical ubuntu linux 17.04

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

canonical ubuntu linux 17.10

x libxfont

Vendor Advisories

Debian Bug report logs - #883929 libxfont: CVE-2017-16611: User can trigger reads on special files as root allowing for DoS Package: src:libxfont; Maintainer for src:libxfont is Debian X Strike Force <debian-x@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 9 Dec 2017 13:45:02 UTC ...
libXfont could be made to access arbitrary files, including special device files ...
In libXfont before 154 and libXfont2 before 203, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files ...