Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server.
References
Link | Resource |
---|---|
https://cgit.freedesktop.org/xorg/xserver/commit/?id=05442de962d3dc624f79fc1a00eca3ffc5489ced | Patch Third Party Advisory |
https://bugzilla.suse.com/show_bug.cgi?id=1035283 | Issue Tracking Third Party Advisory |
http://www.securityfocus.com/bid/99543 | Third Party Advisory VDB Entry |
http://www.debian.org/security/2017/dsa-3905 |
Configurations
Information
Published : 2017-07-06 04:29
Updated : 2019-10-02 17:03
NVD link : CVE-2017-10972
Mitre link : CVE-2017-10972
JSON object : View
CWE
CWE-665
Improper Initialization
Products Affected
x.org
- xorg-server