CVE-2017-16611

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
01/12/2017
Last modified:
20/04/2025

Description

In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:17.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
cpe:2.3:a:x:libxfont:*:*:*:*:*:*:*:* 1.0.0 (including) 1.5.4 (excluding)
cpe:2.3:a:x:libxfont:*:*:*:*:*:*:*:* 2.0.0 (including) 2.0.3 (excluding)