Unrated severityNVD Advisory· Published Jan 24, 2018· Updated Sep 16, 2024
CVE-2017-12178
CVE-2017-12178
Description
xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
Affected products
13- osv-coords12 versionspkg:rpm/suse/xorg-x11-server&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/xorg-x11-server&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/xorg-x11-server&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/xorg-x11-server&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/xorg-x11-server&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/xorg-x11-server&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2pkg:rpm/suse/xorg-x11-server&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/xorg-x11-server&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/xorg-x11-server&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/xorg-x11-server&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/xorg-x11-server&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/xorg-x11-server&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3
< 7.6_1.18.3-76.15.2+ 11 more
- (no CPE)range: < 7.6_1.18.3-76.15.2
- (no CPE)range: < 7.6_1.18.3-76.15.2
- (no CPE)range: < 7.4-27.122.16.1
- (no CPE)range: < 7.6_1.18.3-76.15.2
- (no CPE)range: < 7.6_1.18.3-76.15.2
- (no CPE)range: < 7.6_1.18.3-76.15.2
- (no CPE)range: < 7.4-27.122.16.1
- (no CPE)range: < 7.6_1.18.3-76.15.2
- (no CPE)range: < 7.6_1.18.3-76.15.2
- (no CPE)range: < 7.4-27.122.16.1
- (no CPE)range: < 7.6_1.18.3-76.15.2
- (no CPE)range: < 7.6_1.18.3-76.15.2
- The X.Org Foundation/xorg-x11-serverv5Range: before 1.19.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- security.gentoo.org/glsa/201711-05mitrevendor-advisoryx_refsource_GENTOO
- www.debian.org/security/2017/dsa-4000mitrevendor-advisoryx_refsource_DEBIAN
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_CONFIRM
- cgit.freedesktop.org/xorg/xserver/commit/mitrex_refsource_CONFIRM
- lists.debian.org/debian-lts-announce/2017/11/msg00032.htmlmitremailing-listx_refsource_MLIST
News mentions
0No linked articles in our index yet.