The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifications in received data.
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "ubuntu_priority": "low", "binaries": [ { "binary_version": "2:1.0.10-1ubuntu0.16.04.1~esm1", "binary_name": "libxv-dev" }, { "binary_version": "2:1.0.10-1ubuntu0.16.04.1~esm1", "binary_name": "libxv-dev-dbgsym" }, { "binary_version": "2:1.0.10-1ubuntu0.16.04.1~esm1", "binary_name": "libxv1" }, { "binary_version": "2:1.0.10-1ubuntu0.16.04.1~esm1", "binary_name": "libxv1-dbg" }, { "binary_version": "2:1.0.10-1ubuntu0.16.04.1~esm1", "binary_name": "libxv1-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "2:1.0.11-1", "binary_name": "libxv-dev" }, { "binary_version": "2:1.0.11-1", "binary_name": "libxv1" }, { "binary_version": "2:1.0.11-1", "binary_name": "libxv1-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "2:1.0.11-1", "binary_name": "libxv-dev" }, { "binary_version": "2:1.0.11-1", "binary_name": "libxv1" }, { "binary_version": "2:1.0.11-1", "binary_name": "libxv1-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "2:1.0.11-1", "binary_name": "libxv-dev" }, { "binary_version": "2:1.0.11-1", "binary_name": "libxv1" }, { "binary_version": "2:1.0.11-1", "binary_name": "libxv1-dbgsym" } ] }