CVE-2015-3164: Low severity opensuse vulnerability
Published Jul 1, 2015
·Updated
The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.
Affected Software
19 affected components
openSUSE openSUSE=13.2
X.Org xorg-server=1.16.0
X.Org xorg-server=1.16.1
X.Org xorg-server=1.16.1.901
X.Org xorg-server=1.16.2
X.Org xorg-server=1.16.2.901
X.Org xorg-server=1.16.3
X.Org xorg-server=1.16.4
X.Org xorg-server=1.16.99.901
X.Org xorg-server=1.16.99.902
X.Org xorg-server=1.17.0
X.Org xorg-server=1.17.1
X.Org X Server=1.16.0
X.Org X Server=1.16.1
X.Org X Server=1.16.1.901
X.Org X Server=1.16.2
X.Org X Server=1.16.2.901
X.Org X Server=1.16.3
X.Org X Server=1.17.0
Event History
Jul 1, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2015-3164?
CVE-2015-3164 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2015-3164?
To fix CVE-2015-3164, update XWayland to version 1.17.2 or later.
3
What versions of XWayland are affected by CVE-2015-3164?
XWayland versions 1.16.x and 1.17.x before 1.17.2 are affected by CVE-2015-3164.
4
What impact does CVE-2015-3164 have on systems?
CVE-2015-3164 allows local users to read from or send information to arbitrary X11 clients.
5
Is CVE-2015-3164 a local or remote vulnerability?
CVE-2015-3164 is considered a local vulnerability, as it requires local access to the system.