Vulnerability CVE-2017-12177: Information

Description

xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.

Severity: CRITICAL (9.8) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Published: Jan. 24, 2018
Modified: Oct. 10, 2019
Error type identifier: CWE-190

Fixed packages

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://cgit.freedesktop.org/xorg/xserver/commit/?id=4ca68b878e851e2136c234f40a25008297d8d831
  • Patch
  • Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1509218
  • Issue Tracking
  • Patch
  • Third Party Advisory
  • VDB Entry
DSA-4000
  • Third Party Advisory
GLSA-201711-05
  • Third Party Advisory
  • VDB Entry
[debian-lts-announce] 20171122 [SECURITY] [DLA 1186-1] xorg-server security update
  • Mailing List
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:a:x.org:xorg-server:*:*:*:*:*:*:*:*
      End excliding
      1.19.5