Security update for libXtst
SUSE Patch
security@suse.de
SUSE Security Team
openSUSE-SU-2016:3037-1
Final
1
1
2016-12-07T10:41:15Z
current
2016-12-07T10:41:15Z
2016-12-07T10:41:15Z
cve-database/bin/generate-cvrf.pl
2017-02-24T01:00:00Z
Security update for libXtst
This update of libXtst fixes the following security issue:
- malicious data sent from an untrusted or compromised X server could cause
out of boundary memory access or endless loops (Denial of Service).
(boo#1003012, CVE-2016-7951, CVE-2016-7952)
The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)
http://lists.opensuse.org/opensuse-updates/2016-12/msg00051.html
E-Mail link for openSUSE-SU-2016:3037-1
https://www.suse.com/support/security/rating/
SUSE Security Ratings
openSUSE 13.2
libXtst-1.2.2-4.3.1
libXtst-debugsource-1.2.2-4.3.1
libXtst-devel-1.2.2-4.3.1
libXtst-devel-32bit-1.2.2-4.3.1
libXtst6-1.2.2-4.3.1
libXtst6-32bit-1.2.2-4.3.1
libXtst6-debuginfo-1.2.2-4.3.1
libXtst6-debuginfo-32bit-1.2.2-4.3.1
libXtst-1.2.2-4.3.1 as a component of openSUSE 13.2
libXtst-debugsource-1.2.2-4.3.1 as a component of openSUSE 13.2
libXtst-devel-1.2.2-4.3.1 as a component of openSUSE 13.2
libXtst-devel-32bit-1.2.2-4.3.1 as a component of openSUSE 13.2
libXtst6-1.2.2-4.3.1 as a component of openSUSE 13.2
libXtst6-32bit-1.2.2-4.3.1 as a component of openSUSE 13.2
libXtst6-debuginfo-1.2.2-4.3.1 as a component of openSUSE 13.2
libXtst6-debuginfo-32bit-1.2.2-4.3.1 as a component of openSUSE 13.2
Multiple integer overflows in X.org libXtst before 1.2.3 allow remote X servers to trigger out-of-bounds memory access operations by leveraging the lack of range checks.
CVE-2016-7951
openSUSE 13.2:libXtst-1.2.2-4.3.1
openSUSE 13.2:libXtst-debugsource-1.2.2-4.3.1
openSUSE 13.2:libXtst-devel-1.2.2-4.3.1
openSUSE 13.2:libXtst-devel-32bit-1.2.2-4.3.1
openSUSE 13.2:libXtst6-1.2.2-4.3.1
openSUSE 13.2:libXtst6-32bit-1.2.2-4.3.1
openSUSE 13.2:libXtst6-debuginfo-1.2.2-4.3.1
openSUSE 13.2:libXtst6-debuginfo-32bit-1.2.2-4.3.1
moderate
5.1
AV:N/AC:H/Au:N/C:P/I:P/A:P
Please Install the update.
http://lists.opensuse.org/opensuse-updates/2016-12/msg00051.html
https://www.suse.com/security/cve/CVE-2016-7951.html
CVE-2016-7951
https://bugzilla.suse.com/1003012
SUSE Bug 1003012
X.org libXtst before 1.2.3 allows remote X servers to cause a denial of service (infinite loop) via a reply in the (1) XRecordStartOfData, (2) XRecordEndOfData, or (3) XRecordClientDied category without a client sequence and with attached data.
CVE-2016-7952
openSUSE 13.2:libXtst-1.2.2-4.3.1
openSUSE 13.2:libXtst-debugsource-1.2.2-4.3.1
openSUSE 13.2:libXtst-devel-1.2.2-4.3.1
openSUSE 13.2:libXtst-devel-32bit-1.2.2-4.3.1
openSUSE 13.2:libXtst6-1.2.2-4.3.1
openSUSE 13.2:libXtst6-32bit-1.2.2-4.3.1
openSUSE 13.2:libXtst6-debuginfo-1.2.2-4.3.1
openSUSE 13.2:libXtst6-debuginfo-32bit-1.2.2-4.3.1
moderate
5.1
AV:N/AC:H/Au:N/C:P/I:P/A:P
Please Install the update.
http://lists.opensuse.org/opensuse-updates/2016-12/msg00051.html
https://www.suse.com/security/cve/CVE-2016-7952.html
CVE-2016-7952
https://bugzilla.suse.com/1003012
SUSE Bug 1003012