CVE-2017-12180: Input Validation
Missing length validation was found in XFree86 VidModeExtension.
Upstream patch:
https://cgit.freedesktop.org/xorg/xserver/commit/?id=1b1d4c04695dced2463404174b50b3581dbd857b
Other sources
xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12180?
CVE-2017-12180 has a moderate severity level due to the potential for denial of service conditions.
How do I fix CVE-2017-12180?
To fix CVE-2017-12180, update to the patched versions of xorg-server as specified in the vendor's advisory.
Which versions of xorg-server are affected by CVE-2017-12180?
CVE-2017-12180 affects multiple versions of xorg-server including versions prior to 1.19.5 and some versions on Debian and Red Hat.
What systems are vulnerable to CVE-2017-12180?
Systems running vulnerable versions of xorg-server on Debian and Red Hat distributions are susceptible to CVE-2017-12180.
Is there a patch available for CVE-2017-12180?
Yes, a patch for CVE-2017-12180 has been released and is available in the latest updates for affected packages.