libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack vector exists against the related code in cursor/xcursor.c in Wayland through 1.14.0.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libxcursor | Feb 21, 2018 | Dec 1, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 1, 2017 |
| Debian | — | Upgrade waylandUpgrade libxcursor | Dec 10, 2017 | Nov 29, 2017 |
| Freebsd | — | Upgrade libXcursor | Dec 20, 2017 | Dec 17, 2017 |
| Gentoo Linux | — | Upgrade x11-libs/libXcursor. | Jan 8, 2018 | Dec 1, 2017 |
| Huawei Euleros 2_0_sp1 | — | — | Jan 19, 2018 | Dec 1, 2017 |
| Huawei Euleros 2_0_sp2 | — | — | Jan 19, 2018 | Dec 1, 2017 |
| Oracle Solaris | — | Upgrade x11/library/libxfont to version 1.5.4-0.175.3.31.0.2.1545 on Solaris 11.3Upgrade x11/library/libxcursor to version 1.1.15-0.175.3.31.0.2.1545 on Solaris 11.3 | Apr 18, 2018 | Dec 1, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 25, 2017 |
| Suse | — | Upgrade xorg-x11-libsUpgrade xorg-x11-develUpgrade libXcursor-develUpgrade xorg-x11-libs-32bitUpgrade xorg-x11-libs-x86Upgrade libXcursor1-32bitUpgrade xorg-x11-devel-32bitUpgrade libXcursor1 | Dec 5, 2017 | Nov 29, 2017 |
| Ubuntu | — | Upgrade libwayland-cursor0Upgrade libwayland-devUpgrade libxcursor1Upgrade libwayland-server0Upgrade libwayland-docUpgrade libwayland-binUpgrade libwayland-client0 | Nov 29, 2017 | Nov 29, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub