First published: Sat Aug 25 2018(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libxkbcommon | <0.8.2 | 0.8.2 |
debian/libxkbcommon | 1.0.3-2 1.5.0-1 1.6.0-1 | |
libxkbcommon-dev | <=0.8.1 | |
dbus-common | <=0.8.1 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Libxkbcommon0 | <=0.8.1 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15861 is considered a high-severity vulnerability due to its potential to allow local attackers to crash the xkbcommon parser.
To mitigate CVE-2018-15861, you should upgrade libxkbcommon to version 0.8.2 or later.
CVE-2018-15861 affects versions of libxkbcommon prior to 0.8.2 and specific versions on Debian and Ubuntu.
CVE-2018-15861 is not remotely exploitable as it requires local access to exploit through crafted keymap files.
CVE-2018-15861 involves a NULL pointer dereference attack that can lead to crashes in the xkbcommon parser.