CVE-2016-7952

Priority
Description
X.org libXtst before 1.2.3 allows remote X servers to cause a denial of
service (infinite loop) via a reply in the (1) XRecordStartOfData, (2)
XRecordEndOfData, or (3) XRecordClientDied category without a client
sequence and with attached data.
Notes
 sbeattie> same commit as CVE-2016-7951
 msalatore> patch released in 2:1.2.2-1+deb8u1
Package
Upstream:released (2:1.2.2-1+deb8u1, 1.2.3)
Ubuntu 12.04 ESM (Precise Pangolin):DNE (precise was needed)
Ubuntu 14.04 LTS (Trusty Tahr):needed
Ubuntu 16.04 LTS (Xenial Xerus):needed
Ubuntu 18.04 LTS (Bionic Beaver):needed
Ubuntu 18.10 (Cosmic Cuttlefish):needed
Ubuntu 19.04 (Disco Dingo):needed
Patches:
Upstream:https://cgit.freedesktop.org/xorg/lib/libXtst/commit/?id=9556ad67af3129ec4a7a4f4b54a0d59701beeae3
More Information

Updated: 2019-01-14 21:20:48 UTC (commit 51f9b73af244ba86b9321e46e526586c25a8e060)