CVE-2017-16612: Integer Overflow
Last updated 24 July 2024
Other sources
libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack vector exists against the related code in cursor/xcursor.c in Wayland through 1.14.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-16612?
CVE-2017-16612 is a vulnerability in libXcursor and Wayland that could lead to heap buffer overflows when processing malicious cursors.
What is the severity of CVE-2017-16612?
The severity of CVE-2017-16612 is high with a severity value of 7.5.
How can I fix CVE-2017-16612 in libXcursor?
To fix CVE-2017-16612 in libXcursor, update to version 1.1.15 or higher.
How can I fix CVE-2017-16612 in Wayland?
To fix CVE-2017-16612 in Wayland, update to version 1.14.0 or higher.
Are there any references available for CVE-2017-16612?
Yes, you can find references for CVE-2017-16612 at the following URLs: [Reference 1](https://security-tracker.debian.org/tracker/CVE-2017-16612), [Reference 2](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16612), [Reference 3](https://cgit.freedesktop.org/xorg/lib/libXcursor/commit/?id=4794b5dd34688158fb51a2943032569d3780c4b8).