CVE-2012-0064: Medium severity x11 fonts utilities vulnerability

Published Jan 19, 2012
·
Updated

It was found that XKB actions for debugging X.org clients were enabled by default. This could cause a screen locking application such as gnome-screensaver to be killed when those key combinations were triggered.

The debugging key actions were introduced in the following commit: http://cgit.freedesktop.org/xorg/xserver/commit/?id=7d2543a3cb3089241982ce4f8984fd723d5312a1

Reference: http://thread.gmane.org/gmane.comp.security.oss.general/6725

Mitigation: http://thread.gmane.org/gmane.comp.security.oss.general/6725/focus=6731

Other sources

xkeyboard-config before 2.5 in X.Org before 7.6 enables certain XKB debugging functions by default, which allows physically proximate attackers to bypass an X screen lock via keyboard combinations that break the input grab.

MITRE

Affected Software

27 affected components
X X.Org X11<=7.5
X X.Org X11=1.0
X X.Org X11=3.0
X X.Org X11=4.0
X X.Org X11=5.0
X X.Org X11=6.0
X X.Org X11=6.1
X X.Org X11=6.3
X X.Org X11=6.4
X X.Org X11=6.5.1
X X.Org X11=6.6
X X.Org X11=6.7
X X.Org X11=6.8
X X.Org X11=6.8.1
X X.Org X11=6.8.2
X X.Org X11=6.9.0
X X.Org X11=7.0
X X.Org X11=7.1
X X.Org X11=7.2
X X.Org X11=7.3
X X.Org X11=7.4
X X.Org X11=7.5
Xkeyboard Config Project Xkeyboard-config<=2.4
Xkeyboard Config Project Xkeyboard-config=2.0
Xkeyboard Config Project Xkeyboard-config=2.1
Xkeyboard Config Project Xkeyboard-config=2.2
Xkeyboard Config Project Xkeyboard-config=2.3

Event History

Jan 19, 2012
Data Sourced
06:13 AM
DescriptionSeverityAffected Software
Feb 10, 2014
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2012-0064?

CVE-2012-0064 is categorized as a medium-severity vulnerability due to its potential to disrupt screen locking applications.

2

How do I fix CVE-2012-0064?

To mitigate CVE-2012-0064, disable the debugging XKB actions in your X server configuration.

3

What software is affected by CVE-2012-0064?

CVE-2012-0064 affects multiple versions of X.Org X11 and Debian Keyboard Configuration software.

4

Can CVE-2012-0064 lead to unauthorized access?

While CVE-2012-0064 primarily disrupts the screen locking mechanism, it does not directly enable unauthorized access.

5

Is there a workaround for CVE-2012-0064?

A temporary workaround for CVE-2012-0064 is to use alternative screen locking mechanisms that are not affected by the XKB debugging actions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203