PublicDateAtUSN: 2016-12-31 Candidate: CVE-2016-10164 PublicDate: 2017-02-01 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10164 http://www.openwall.com/lists/oss-security/2017/01/22/2 https://ubuntu.com/security/notices/USN-3185-1 Description: Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via (1) the number of extensions or (2) their concatenated length in a crafted XPM file, which triggers a heap-based buffer overflow. Ubuntu-Description: Notes: tyhicks> See oss-security thread for a test case Bugs: Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_libxpm: upstream: https://cgit.freedesktop.org/xorg/lib/libXpm/commit/?id=d1167418f0fd02a27f617ec5afd6db053afbe185 upstream_libxpm: released (1:3.5.12-1) precise_libxpm: released (1:3.5.9-4ubuntu0.1) trusty_libxpm: released (1:3.5.10-1ubuntu0.1) trusty/esm_libxpm: released (1:3.5.10-1ubuntu0.1) vivid/stable-phone-overlay_libxpm: DNE vivid/ubuntu-core_libxpm: DNE xenial_libxpm: released (1:3.5.11-1ubuntu0.16.04.1) esm-infra/xenial_libxpm: released (1:3.5.11-1ubuntu0.16.04.1) yakkety_libxpm: released (1:3.5.11-1ubuntu0.16.10.1) devel_libxpm: not-affected (1:3.5.12-1)