First published: Fri May 18 2012(Updated: )
Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibly execute arbitrary code via format string specifiers in an input device name.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Xorg-x11-drv-void | =1.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2118 has a high severity rating due to its potential to cause denial of service and execute arbitrary code.
Fixing CVE-2012-2118 requires updating to a patched version of X.Org X11 that addresses the format string vulnerability.
CVE-2012-2118 allows attackers to potentially execute arbitrary code and cause denial of service through crafted input device names.
CVE-2012-2118 specifically affects versions of X.Org X11 up to and including 1.11.
Yes, CVE-2012-2118 can be exploited remotely if an attacker can send crafted input device names to an affected system.