CVE-2017-12178: Input Validation
Wrong extra length check in ProcXIChangeHierarchy function was found.
Upstream patch:
https://cgit.freedesktop.org/xorg/xserver/commit/?id=859b08d523307eebde7724fd1a0789c44813e821
Other sources
xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12178?
CVE-2017-12178 is classified as a moderate severity vulnerability.
How do I fix CVE-2017-12178?
To fix CVE-2017-12178, update to a version of the xorg-server that includes the patch, such as xorg-server 2:1.20.4-1+deb10u4 or later.
What systems are affected by CVE-2017-12178?
CVE-2017-12178 affects specific versions of xorg-server in Debian, Red Hat, and other distributions.
What is the impact of CVE-2017-12178?
The impact of CVE-2017-12178 involves a potential bypass of security protections due to improper length checks.
Is there a public reference for CVE-2017-12178?
Yes, CVE-2017-12178 has public references in bug tracking systems and security trackers for more detailed information.