Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-10164

Опубликовано: 12 дек. 2016
Источник: redhat
CVSS3: 5.8
EPSS Низкий

Описание

Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via (1) the number of extensions or (2) their concatenated length in a crafted XPM file, which triggers a heap-based buffer overflow.

An integer overflow flaw leading to a heap-based buffer overflow was found in libXpm. An attacker could use this flaw to crash an application using libXpm via a specially crafted XPM file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libXpmWill not fix
Red Hat Enterprise Linux 6libXpmWill not fix
Red Hat Enterprise Linux 7libdrmFixedRHSA-2017:186501.08.2017
Red Hat Enterprise Linux 7libepoxyFixedRHSA-2017:186501.08.2017
Red Hat Enterprise Linux 7libevdevFixedRHSA-2017:186501.08.2017
Red Hat Enterprise Linux 7libfontencFixedRHSA-2017:186501.08.2017
Red Hat Enterprise Linux 7libICEFixedRHSA-2017:186501.08.2017
Red Hat Enterprise Linux 7libinputFixedRHSA-2017:186501.08.2017
Red Hat Enterprise Linux 7libvdpauFixedRHSA-2017:186501.08.2017
Red Hat Enterprise Linux 7libwacomFixedRHSA-2017:186501.08.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1416410libXpm: Out-of-bounds write in XPM extension parsing

EPSS

Процентиль: 88%
0.03739
Низкий

5.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 9 лет назад

Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via (1) the number of extensions or (2) their concatenated length in a crafted XPM file, which triggers a heap-based buffer overflow.

CVSS3: 9.8
nvd
около 9 лет назад

Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via (1) the number of extensions or (2) their concatenated length in a crafted XPM file, which triggers a heap-based buffer overflow.

CVSS3: 9.8
debian
около 9 лет назад

Multiple integer overflows in libXpm before 3.5.12, when a program req ...

suse-cvrf
почти 9 лет назад

Security update for libXpm

suse-cvrf
почти 9 лет назад

Security update for xorg-x11-libXpm

EPSS

Процентиль: 88%
0.03739
Низкий

5.8 Medium

CVSS3