PT-2025-25662 · Xfixes+6 · Xfixes+6

Julian Suleder

+1

·

Published

2025-03-27

·

Updated

2025-12-12

·

CVE-2025-49177

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions The product name cannot be determined.
Description A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read unintended memory from previous requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

ALSA-2025:9304
AZL-64271
BDU:2025-11959
CVE-2025-49177
DSA-5947-1
MGASA-2025-0199
OPENSUSE-SU-2025:15310-1
OPENSUSE-SU-2025:15311-1
RHSA-2025:10258
RHSA-2025:9303
RHSA-2025:9304
RHSA-2025_9303
SUSE-SU-2025:01974-1
SUSE-SU-2025:01975-1
SUSE-SU-2025:01979-1
SUSE-SU-2025:01980-1
SUSE-SU-2025:01981-1
SUSE-SU-2025_01979-1
SUSE-SU-2025_01980-1
SUSE-SU-2025_01981-1
USN-7573-1

Affected Products

Astra Linux
Debian
Linuxmint
Red Hat
Suse
Ubuntu
Xfixes