Vulnerability CVE-2017-16611: Information
Description
In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.
Severity: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
libXfont | sisyphus | 1.5.4-alt1.S1 | 1.5.4-alt2 | ALT-PU-2017-2728-1 | 195757 | Fixed |
libXfont | p10 | 1.5.4-alt1.S1 | 1.5.4-alt2 | ALT-PU-2017-2728-1 | 195757 | Fixed |
libXfont | p9 | 1.5.4-alt1.S1 | 1.5.4-alt2 | ALT-PU-2017-2728-1 | 195757 | Fixed |
libXfont | p8 | 1.5.4-alt1.M80P.1 | 1.5.4-alt1.M80P.1 | ALT-PU-2017-2733-1 | 195759 | Fixed |
libXfont | c10f1 | 1.5.4-alt1.S1 | 1.5.4-alt2 | ALT-PU-2017-2728-1 | 195757 | Fixed |
libXfont | c9f2 | 1.5.4-alt1.S1 | 1.5.4-alt2 | ALT-PU-2017-2728-1 | 195757 | Fixed |
libXfont2 | sisyphus | 2.0.3-alt1.S1 | 2.0.6-alt1 | ALT-PU-2017-2729-1 | 195758 | Fixed |
libXfont2 | p10 | 2.0.3-alt1.S1 | 2.0.4-alt1 | ALT-PU-2017-2729-1 | 195758 | Fixed |
libXfont2 | p9 | 2.0.3-alt1.S1 | 2.0.3-alt2 | ALT-PU-2017-2729-1 | 195758 | Fixed |
libXfont2 | p8 | 2.0.3-alt1.M80P.1 | 2.0.3-alt1.M80P.1 | ALT-PU-2017-2734-1 | 195760 | Fixed |
libXfont2 | c10f1 | 2.0.3-alt1.S1 | 2.0.4-alt1 | ALT-PU-2017-2729-1 | 195758 | Fixed |
libXfont2 | c9f2 | 2.0.3-alt1.S1 | 2.0.3-alt2 | ALT-PU-2017-2729-1 | 195758 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://bugzilla.suse.com/show_bug.cgi?id=1050459 |
|
USN-3500-1 |
|
[oss-security] 20171128 CVE-2017-16611 libXfont Open files with O_NOFOLLOW |
|
[freedesktop-xorg-announce] 20171128 libXfont 1.5.4 |
|
[freedesktop-xorg-announce] 20171128 libXfont2 2.0.3 |
|
http://security.cucumberlinux.com/security/details.php?id=155 |
|
GLSA-201801-10 |
|
[debian-lts-announce] 20220125 [SECURITY] [DLA 2901-1] libxfont security update |
|