ALPINE-CVE-2017-13723 PUBLISHED CVSS 7.800000190734863 HIGH

In X.Org Server (aka xserver and xorg-server) before 1.19.4, a local attacker authenticated to the X server could overflow a global buffer, causing crashes of the X server or potentially other problems by injecting large or malformed XKB related atoms and accessing them via xkbcomp.

Risk Scores

CVSS v3.0
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.7xorg-server0, 1.9.4-r1, 1.9.4-r0
Alpine:v3.12xorg-server1.10.0.901-r0, 1.9.4-r1, 1.9.4-r0
Alpine:v3.6xorg-server1.9.4-r1, 0, 1.10.0-r0
Alpine:v3.8xorg-server1.6.0-r4, 1.6.1-r0, 1.6.1-r1
Alpine:v3.9xorg-server1.9.4-r1, 0, 1.10.0-r0
Alpine:v3.10xorg-server1.18.1-r0, 1.9.4-r1, 1.9.4-r0
Alpine:v3.11xorg-server1.10.0-r0, 1.9.4-r1, 1.9.4-r0

Timeline

References

Open in Interactive Console →