libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack vector exists against the related code in cursor/xcursor.c in Wayland through 1.14.0.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1201-1 | libxcursor security update |
Debian DSA |
DSA-4059-1 | libxcursor security update |
EUVD |
EUVD-2017-7803 | libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack vector exists against the related code in cursor/xcursor.c in Wayland through 1.14.0. |
Ubuntu USN |
USN-3501-1 | libxcursor vulnerability |
Ubuntu USN |
USN-3622-1 | Wayland vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T20:27:04.328Z
Reserved: 2017-11-06T00:00:00
Link: CVE-2017-16612
No data.
Status : Deferred
Published: 2017-12-01T17:29:00.510
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-16612
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN