Multiple integer overflows in X.org libXi before 1.7.7 allow remote X servers to cause a denial of service (out-of-bounds memory access or infinite loop) via vectors involving length fields.
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "ubuntu_priority": "low", "binaries": [ { "binary_version": "2:1.7.6-1ubuntu0.1~esm1", "binary_name": "libxi-dev" }, { "binary_version": "2:1.7.6-1ubuntu0.1~esm1", "binary_name": "libxi-dev-dbgsym" }, { "binary_version": "2:1.7.6-1ubuntu0.1~esm1", "binary_name": "libxi6" }, { "binary_version": "2:1.7.6-1ubuntu0.1~esm1", "binary_name": "libxi6-dbg" }, { "binary_version": "2:1.7.6-1ubuntu0.1~esm1", "binary_name": "libxi6-dbgsym" }, { "binary_version": "2:1.7.6-1ubuntu0.1~esm1", "binary_name": "libxi6-udeb" }, { "binary_version": "2:1.7.6-1ubuntu0.1~esm1", "binary_name": "libxi6-udeb-dbgsym" } ] }