Vulnerability Description
In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | 8.0 |
| Canonical | Ubuntu Linux | 14.04 |
| X | Libxfont | >= 1.0.0, < 1.5.4 |
Related Weaknesses (CWE)
References
- http://security.cucumberlinux.com/security/details.php?id=155Third Party Advisory
- http://www.openwall.com/lists/oss-security/2017/11/28/7Mailing ListPatchThird Party Advisory
- http://www.ubuntu.com/usn/USN-3500-1Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1050459Issue TrackingTool SignatureVDB Entry
- https://lists.debian.org/debian-lts-announce/2022/01/msg00028.htmlIssue TrackingMailing ListThird Party Advisory
- https://marc.info/?l=freedesktop-xorg-announce&m=151188044218304&w=2PatchThird Party Advisory
- https://marc.info/?l=freedesktop-xorg-announce&m=151188049718337&w=2PatchThird Party Advisory
- https://security.gentoo.org/glsa/201801-10Third Party Advisory
- http://security.cucumberlinux.com/security/details.php?id=155Third Party Advisory
- http://www.openwall.com/lists/oss-security/2017/11/28/7Mailing ListPatchThird Party Advisory
- http://www.ubuntu.com/usn/USN-3500-1Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1050459Issue TrackingTool SignatureVDB Entry
- https://lists.debian.org/debian-lts-announce/2022/01/msg00028.htmlIssue TrackingMailing ListThird Party Advisory
- https://marc.info/?l=freedesktop-xorg-announce&m=151188044218304&w=2PatchThird Party Advisory
- https://marc.info/?l=freedesktop-xorg-announce&m=151188049718337&w=2PatchThird Party Advisory
FAQ
What is CVE-2017-16611?
CVE-2017-16611 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be trigger...
How severe is CVE-2017-16611?
CVE-2017-16611 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-16611?
Check the references section above for vendor advisories and patch information. Affected products include: Debian Debian Linux, Canonical Ubuntu Linux, X Libxfont.