CVE-2017-12176: Input Validation
Missing extra length validation was found in ProcEstablishConnection function.
Upstream patch:
https://cgit.freedesktop.org/xorg/xserver/commit/?id=b747da5e25be944337a9cd1415506fc06b70aa81
Other sources
xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12176?
CVE-2017-12176 has a moderate severity level due to missing extra length validation in the ProcEstablishConnection function.
How do I fix CVE-2017-12176?
To fix CVE-2017-12176, update the xorg-server package to one of the patched versions provided by the vendor.
What versions of xorg-server are affected by CVE-2017-12176?
CVE-2017-12176 affects multiple xorg-server versions including those prior to 1.20.4-1+deb10u4 and 1.19.5.
Which operating systems are impacted by CVE-2017-12176?
CVE-2017-12176 impacts Debian and Red Hat Linux distributions where vulnerable versions of xorg-server are installed.
Is CVE-2017-12176 related to a specific function in xorg-server?
Yes, CVE-2017-12176 is specifically related to the ProcEstablishConnection function in the xorg-server code.