CVE-2017-16611
Summary
| CVE | CVE-2017-16611 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-12-01 17:29:00 UTC |
| Updated | 2022-02-20 06:06:00 UTC |
| Description | In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Bug 1050459 – VUL-1: CVE-2017-16611: libXfont,xorg-x11-libs:: User can trigger reads on special files as root allowing for DoS |
CONFIRM |
bugzilla.suse.com |
Issue Tracking, Tool Signature, VDB Entry |
| CLD-155 Details |
MISC |
security.cucumberlinux.com |
Third Party Advisory |
| [SECURITY] [DLA 2901-1] libxfont security update |
MLIST |
lists.debian.org |
|
| LibXfont, LibXfont2: Arbitrary file access (GLSA 201801-10) — Gentoo Security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| '[ANNOUNCE] libXfont 1.5.4' - MARC |
MLIST |
marc.info |
Patch, Third Party Advisory |
| '[ANNOUNCE] libXfont2 2.0.3' - MARC |
MLIST |
marc.info |
Patch, Third Party Advisory |
| oss-security - CVE-2017-16611 libXfont Open files with O_NOFOLLOW |
MLIST |
www.openwall.com |
Mailing List, Patch, Third Party Advisory |
| USN-3500-1: libXfont vulnerability | Ubuntu |
UBUNTU |
www.ubuntu.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179036 Debian Security Update for libxfont (DLA 2901-1)
- 500339 Alpine Linux Security Update for libxfont
- 500369 Alpine Linux Security Update for libxfont2
- 504103 Alpine Linux Security Update for libxfont
- 710261 Gentoo Linux LibXfont, LibXfont2 Arbitrary file access Vulnerability (GLSA 201801-10)