CVE-2017-16612
Summary
| CVE | CVE-2017-16612 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-12-01 17:29:00 UTC |
| Updated | 2018-04-11 01:29:00 UTC |
| Description | libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack vector exists against the related code in cursor/xcursor.c in Wayland through 1.14.0. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Bug 1065386 – VUL-0: CVE-2017-16612: libXcursor: heap overflows when parsing malicious files |
CONFIRM |
bugzilla.suse.com |
Issue Tracking, Tool Signature, VDB Entry |
| wayland/wayland - Wayland Compositor Infrastructure (mirrored from https://gitlab.freedesktop.org/wayland/wayland) |
MISC |
cgit.freedesktop.org |
|
| '[ANNOUNCE] libXcursor 1.1.15' - MARC |
MLIST |
marc.info |
Third Party Advisory |
| oss-security - CVE-2017-16612 libXcursor: heap overflows when parsing malicious
files |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| CLD-156 Details |
CONFIRM |
security.cucumberlinux.com |
Patch, Third Party Advisory |
| USN-3501-1: libxcursor vulnerability | Ubuntu |
UBUNTU |
www.ubuntu.com |
Third Party Advisory |
| [SECURITY] [DLA 1201-1] libxcursor security update |
MLIST |
lists.debian.org |
|
| USN-3622-1: Wayland vulnerability | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
|
| LibXcursor: User-assisted execution of arbitrary code (GLSA 201801-04) — Gentoo Security |
GENTOO |
security.gentoo.org |
|
| libwayland-cursor heap overflow fix |
MISC |
lists.freedesktop.org |
|
| xorg/lib/libXcursor - X.org libXcursor library. (mirrored from https://gitlab.freedesktop.org/xorg/lib/libxcursor) |
CONFIRM |
cgit.freedesktop.org |
Exploit, Patch, Third Party Advisory |
| Debian -- Security Information -- DSA-4059-1 libxcursor |
DEBIAN |
www.debian.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500337 Alpine Linux Security Update for libxcursor
- 504101 Alpine Linux Security Update for libxcursor
- 710238 Gentoo Linux LibXcursor User-assisted execution of arbitrary code Vulnerability (GLSA 201801-04)