5
CVSSv2

CVE-2017-16612

Published: 01/12/2017 Updated: 11/04/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

libXcursor prior to 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack vector exists against the related code in cursor/xcursor.c in Wayland up to and including 1.14.0.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 9.0

debian debian linux 8.0

canonical ubuntu linux 17.04

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

canonical ubuntu linux 17.10

x libxcursor

Vendor Advisories

Debian Bug report logs - #883792 libxcursor: CVE-2017-16612: heap overflows when parsing malicious files Package: src:libxcursor; Maintainer for src:libxcursor is Debian X Strike Force <debian-x@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 7 Dec 2017 15:33:02 UTC Severity: impo ...
Wayland could be made to crash or run programs if it opened a specially crafted file ...
libxcursor could be made to crash or run programs if it opened a specially crafted file ...
It was discovered that libXcursor, a X cursor management library, is prone to several heap overflows when parsing malicious files An attacker can take advantage of these flaws for arbitrary code execution, if a user is tricked into processing a specially crafted cursor file For the oldstable distribution (jessie), these problems have been fixed i ...
libXcursor before 1115 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, eg, with programs like GIMP It is also possible that an attack vector exists against the related code in cursor/xcursorc in Wayland through 1140 ...
It was discovered that libxcursor before 1115 is vulnerable to heap overflows due to an integer overflow while parsing images and a signedness issue while parsing comments An attacker could use local privileges or trick a user into parsing a malicious file to cause libxcursor to crash, resulting in a denial of service, or possibly execute arbitr ...