PT-2012-3456 · X.Org+2 · X.Org X11R6+2
Vincent Danen
·
Published
2012-12-21
·
Updated
2017-09-19
·
CVE-2012-1699
CVSS v2.0
3.6
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
X.Org X11R6 versions through X11R6.6
XFree86 versions prior to 3.3.3
Description
The issue allows local users to cause a denial of service, resulting in memory corruption and crash, or obtain potentially sensitive information from memory. This is achieved via a SetEventMask request that triggers an invalid pointer dereference due to the ProcSetEventMask function calling the SendErrToClient function with a mask value instead of a pointer.
Recommendations
For X.Org X11R6 versions through X11R6.6, consider updating to a version outside of the affected range to resolve the issue.
For XFree86 versions prior to 3.3.3, update to version 3.3.3 or later to fix the problem.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hp-Ux
X.Org X11R6
Xfree86