Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian: DSA-2661-1 Critical: Xorg-Server Info Disclosure Issue

debian
Calendar Grey April 17, 2013
Debian Logo
Critical patch for Debian xorg-server boosts protection against data leak vulnerabilities.
David Airlie and Peter Hutterer of Red Hat discovered that xorg-server, the Xorg X server was vulnerable to an information disclosure flaw related to input handling and devices hot...

Summary

David Airlie and Peter Hutterer of Red Hat discovered that xorg-server,
the Xorg X server was vulnerable to an information disclosure flaw
related to input handling and devices hotplug.

When an X server is running but not on front (for example because of a VT
switch), a newly plugged input device would still be recognized and
handled by the X server, which would actually transmit input events to
its clients on the background.

This could allow an attacker to recover some input events not intended
for the X clients, including sensitive information.

For the stable distribution (squeeze), this problem has been fixed in
version 2:1.7.7-16.

For the testing distribution (wheezy), this problem has been fixed in
version 2:1.12.4-6.

For the unstable distribution (sid), this problem has been fixed in
version 2:1.12.4-6.

We recommend that you upgrade your xorg-server packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
fou...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: xorg-server
CVE ID: CVE-2013-1940

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here