CVE-2017-12184: Input Validation
Missing length validation was found in XINERAMA extension.
Upstream patch:
https://cgit.freedesktop.org/xorg/xserver/commit/?id=cad5a1050b7184d828aef9c1dd151c3ab649d37e
Other sources
xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12184?
The severity of CVE-2017-12184 is critical with a CVSS score of 9.8.
What is the impact of CVE-2017-12184?
CVE-2017-12184 allows a malicious X client to crash the X server or potentially execute arbitrary code.
Which software versions are affected by CVE-2017-12184?
Versions of xorg-x11-server before 1.19.5 are affected by CVE-2017-12184.
How can I fix CVE-2017-12184?
To fix CVE-2017-12184, update xorg-x11-server to version 1.19.5 or later.
Where can I find more information about CVE-2017-12184?
You can find more information about CVE-2017-12184 at the following references: [Red Hat bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1509225), [X.org commit](https://cgit.freedesktop.org/xorg/xserver/commit/?id=cad5a1050b7184d828aef9c1dd151c3ab649d37e), [Debian security advisory](https://lists.debian.org/debian-lts-announce/2017/11/msg00032.html).