PT-2018-2301 · X.Org Foundation+5 · Libx11+5

Tobias Stoeckmann

·

Publicado

2018-07-27

·

Atualizado

2024-06-15

·

CVE-2018-14599

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libX11 versions 1.6.5 and earlier
Description The issue is related to an off-by-one error in the XListExtensions function, caused by malicious server responses. This can lead to a denial of service (DoS) or possibly other unspecified impacts. The vulnerability can be exploited by a remote attacker using a specially crafted server response.
Recommendations For libX11 versions 1.6.5 and earlier, consider disabling the XListExtensions function as a temporary workaround until a patch is available. Restrict access to the vulnerable ListExt.c component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2452
BDU:2019-00431
CESA-2019_2079
CVE-2018-14599
DLA-1482-1
MGASA-2018-0377
OPENSUSE-SU-2018_2567-1
OPENSUSE-SU-2018_3012-1
OPENSUSE-SU-2024:10918-1
RHSA-2019:2079
RHSA-2019_2079
SUSE-SU-2018:2934-1
SUSE-SU-2018:2955-1
SUSE-SU-2018:3102-1
USN-3758-1
USN-3758-2

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libx11