CVE-2017-12183: Input Validation
Missing length validation was found in XFIXES extension
Upstream patch:
https://cgit.freedesktop.org/xorg/xserver/commit/?id=55caa8b08c84af2b50fbc936cf334a5a93dd7db5
Other sources
xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-12183?
CVE-2017-12183 is a vulnerability in xorg-x11-server before version 1.19.5 that allows a malicious X client to crash the X server or execute arbitrary code.
How severe is CVE-2017-12183?
CVE-2017-12183 has a severity rating of 9.8 out of 10, making it a critical vulnerability.
Which software is affected by CVE-2017-12183?
The xorg-x11-server package versions before 1.19.5 are affected, including Debian Debian Linux version 8.0 and 9.0.
How can I fix CVE-2017-12183?
To fix CVE-2017-12183, make sure you update xorg-x11-server to version 1.19.5 or higher.
Where can I find more information about CVE-2017-12183?
You can find more information about CVE-2017-12183 in the references provided: bugzilla.redhat.com, cgit.freedesktop.org, and lists.debian.org.