CVE-2017-10972 PUBLISHED

Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server.

EPSS 0.56% · 68.1th percentile

Risk Scores

EPSS Score
0.56%
68.1th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSxorg-server-lts-xenial0, 2:1.18.3-1ubuntu2.2~trusty1, 2:1.18.3-1ubuntu2.2~trusty2
Ubuntu:16.04:LTSxorg-server-hwe-16.042:1.18.4-1ubuntu6.1~16.04.1, 0
Ubuntu:16.04:LTSxorg-server2:1.17.2-1ubuntu10, 2:1.17.3-2ubuntu1, 2:1.17.3-2ubuntu2
Ubuntu:14.04:LTSxorg-server0, 2:1.15.1-0ubuntu2.7, 2:1.14.3-3ubuntu2

Timeline

References

Open in Interactive Console →