{
  "threat_severity" : "Moderate",
  "public_date" : "2016-12-12T00:00:00Z",
  "bugzilla" : {
    "description" : "libXpm: Out-of-bounds write in XPM extension parsing",
    "id" : "1416410",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1416410"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.8",
    "cvss3_scoring_vector" : "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L",
    "status" : "verified"
  },
  "cwe" : "CWE-787",
  "details" : [ "Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via (1) the number of extensions or (2) their concatenated length in a crafted XPM file, which triggers a heap-based buffer overflow.", "An integer overflow flaw leading to a heap-based buffer overflow was found in libXpm. An attacker could use this flaw to crash an application using libXpm via a specially crafted XPM file." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libdrm-0:2.4.74-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libepoxy-0:1.3.1-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libevdev-0:1.5.6-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libfontenc-0:1.1.3-3.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libICE-0:1.0.9-9.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libinput-0:1.6.3-2.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libvdpau-0:1.1.1-3.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libwacom-0:0.24-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libX11-0:1.6.5-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libXaw-0:1.0.13-4.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libxcb-0:1.12-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libXcursor-0:1.1.14-8.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libXdmcp-0:1.1.2-6.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libXfixes-0:5.0.3-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libXfont-0:1.5.2-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libXfont2-0:2.0.1-2.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libXi-0:1.7.9-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libxkbcommon-0:0.7.1-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libxkbfile-0:1.0.9-3.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libXpm-0:3.5.12-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libXrandr-0:1.5.1-2.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libXrender-0:0.9.10-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libXt-0:1.1.5-3.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libXtst-0:1.2.3-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libXv-0:1.0.11-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libXvMC-0:1.0.10-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libXxf86vm-0:1.1.4-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "mesa-0:17.0.1-6.20170307.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "mesa-private-llvm-0:3.9.1-3.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "vulkan-0:1.0.39.1-2.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "xcb-proto-0:1.12-2.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "xkeyboard-config-0:2.20-1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-08-01T00:00:00Z",
    "advisory" : "RHSA-2017:1865",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "xorg-x11-proto-devel-0:7.7-20.el7"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 5",
    "fix_state" : "Will not fix",
    "package_name" : "libXpm",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Will not fix",
    "package_name" : "libXpm",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2016-10164\nhttps://nvd.nist.gov/vuln/detail/CVE-2016-10164" ],
  "name" : "CVE-2016-10164",
  "csaw" : false
}