CVE-2017-12177: Integer Overflow
Potential integer overflow vulnerability was found in ProcDbeGetVisualInfo function.
Upstream patch:
https://cgit.freedesktop.org/xorg/xserver/commit/?id=4ca68b878e851e2136c234f40a25008297d8d831
Other sources
xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12177?
The severity of CVE-2017-12177 is critical with a severity value of 9.8.
What is CVE-2017-12177?
CVE-2017-12177 refers to an integer overflow vulnerability in the ProcDbeGetVisualInfo function of xorg-x11-server before version 1.19.5.
How does CVE-2017-12177 impact the X server?
CVE-2017-12177 allows a malicious X client to crash the X server or potentially execute arbitrary code.
How can I fix CVE-2017-12177?
To fix CVE-2017-12177, update xorg-x11-server to version 1.19.5 or higher.
Where can I find more information about CVE-2017-12177?
You can find more information about CVE-2017-12177 at the following references: [Reference 1](https://cgit.freedesktop.org/xorg/xserver/commit/?id=4ca68b878e851e2136c234f40a25008297d8d831), [Reference 2](https://security-tracker.debian.org/tracker/CVE-2017-12177), [Reference 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1509258).