CVE-2017-13721: Medium severity x.org xserver vulnerability
In X.Org Server (aka xserver and xorg-server) before 1.19.4, an attacker authenticated to an X server with the X shared memory extension enabled can cause aborts of the X server or replace shared memory segments of other X clients in the same session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13721?
CVE-2017-13721 has a high severity rating due to its potential for causing X server aborts and malicious manipulation of shared memory segments.
How do I fix CVE-2017-13721?
To fix CVE-2017-13721, update the X.Org Server to a version that is 1.19.4 or higher, such as 2:1.20.4-1+deb10u4.
What systems are affected by CVE-2017-13721?
CVE-2017-13721 affects systems running X.Org Server versions prior to 1.19.4, specifically on Debian GNU/Linux 8.0 and 9.0.
Can CVE-2017-13721 be exploited remotely?
CVE-2017-13721 requires local access since the attacker must be authenticated to the X server to exploit the vulnerability.
What impact does CVE-2017-13721 have on users?
The impact of CVE-2017-13721 can lead to service disruptions as it allows an attacker to abort the X server or alter shared memory segments of other X clients.