|
|
Log in / Subscribe / Register

xorg-server: information leak/denial of service

Package(s):xorg-server CVE #(s):CVE-2015-0255
Created:February 12, 2015 Updated:May 1, 2015
Description: From the X.Org advisory:

Olivier Fourdan from Red Hat has discovered a protocol handling issue in the way the X server code base handles the XkbSetGeometry request.

The issue stems from the server trusting the client to send valid string lengths in the request data. A malicious client with string lengths exceeding the request length can cause the server to copy adjacent memory data into the XKB structs. This data is then available to the client via the XkbGetGeometry request. The data length is at least up to 64k, it is possible to obtain more data by chaining strings, each string length is then determined by whatever happens to be in that 16-bit region of memory.

A similarly crafted request can likely cause the X server to crash.

Alerts:
Debian-LTS DLA-218-1 xorg-server 2015-05-01
Gentoo 201504-06 xorg-server 2015-04-17
Scientific Linux SLSA-2015:0797-1 xorg-x11-server 2015-04-13
CentOS CESA-2015:0797 xorg-x11-server 2015-04-10
Oracle ELSA-2015-0797 xorg-x11-server 2015-04-09
Oracle ELSA-2015-0797 xorg-x11-server 2015-04-09
CentOS CESA-2015:0797 xorg-x11-server 2015-04-10
Red Hat RHSA-2015:0797-01 xorg-x11-server 2015-04-10
Mandriva MDVSA-2015:119 x11-server 2015-03-29
Fedora FEDORA-2015-3948 nx-libs 2015-03-26
Fedora FEDORA-2015-3964 nx-libs 2015-03-26
openSUSE openSUSE-SU-2015:0337-1 xorg-x11-server 2015-02-20
openSUSE openSUSE-SU-2015:0338-1 tigervnc 2015-02-20
Mageia MGASA-2015-0073 x11-server 2015-02-17
Ubuntu USN-2500-1 xorg-server, xorg-server-lts-trusty, xorg-server-lts-utopic 2015-02-17
Debian DSA-3160-1 xorg-server 2015-02-11

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds