CVE-2017-13723 PUBLISHED

In X.Org Server (aka xserver and xorg-server) before 1.19.4, a local attacker authenticated to the X server could overflow a global buffer, causing crashes of the X server or potentially other problems by injecting large or malformed XKB related atoms and accessing them via xkbcomp.

EPSS 0.14% · 33.3th percentile

Risk Scores

EPSS Score
0.14%
33.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSxorg-server-hwe-16.042:1.19.3-1ubuntu1~16.04.2, 2:1.18.4-1ubuntu6.1~16.04.2, 2:1.18.4-1ubuntu6.1~16.04.1
Ubuntu:14.04:LTSxorg-server-lts-xenial2:1.18.3-1ubuntu2.3~trusty1, 0, 2:1.18.3-1ubuntu2.3~trusty2
Ubuntu:14.04:LTSxorg-server2:1.15.0-1ubuntu1, 2:1.15.0-1ubuntu2, 0
Ubuntu:16.04:LTSxorg-server2:1.17.3-2ubuntu2, 2:1.17.3-2ubuntu3, 2:1.17.3-2ubuntu4

Timeline

References

Open in Interactive Console →