Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian: DSA-3160-1 Urgent: Input Leak Vulnerability In Xorg-Server

debian
Calendar Grey February 11, 2015
Debian Logo
Enhance xorg-server installations because of severe input verification vulnerability impacting the Xserver of Debian. Prompt response recommended.
Olivier Fourdan discovered that missing input validation in the Xserver's handling of XkbSetGeometry requests may result in an information leak or denial of service

Summary

Olivier Fourdan discovered that missing input validation in the Xserver's
handling of XkbSetGeometry requests may result in an information leak
or denial of service.

For the stable distribution (wheezy), this problem has been fixed in
version 2:1.12.4-6+deb7u6.

For the unstable distribution (sid), this problem has been fixed in
version 2:1.16.4-1.

We recommend that you upgrade your xorg-server packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: xorg-server
CVE ID: CVE-2015-0255

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here