USN-3362-1
Dashboard / Vulnerabilities / USN-3362-1
USN-3362-1
Summary: xorg-server, xorg-server-hwe-16.04, xorg-server-lts-xenial vulnerabilities
Details: It was discovered that the X.Org X server incorrectly handled endianness conversion of certain X events. An attacker able to connect to an X server, either locally or remotely, could use this issue to crash the server, or possibly execute arbitrary code as an administrator. (CVE-2017-10971) It was discovered that the X.Org X server incorrectly handled endianness conversion of certain X events. An attacker able to connect to an X server, either locally or remotely, could use this issue to possibly obtain sensitive information. (CVE-2017-10972) Eric Sesterhenn discovered that the X.Org X server incorrectly compared MIT cookies. An attacker could possibly use this issue to perform a timing attack and recover the MIT cookie. (CVE-2017-2624)
References: https://ubuntu.com/security/notices/USN-3362-1, https://ubuntu.com/security/CVE-2017-2624, https://ubuntu.com/security/CVE-2017-10971, https://ubuntu.com/security/CVE-2017-10972
Affected packages
Package
Name: xorg-server
Purl: pkg:deb/ubuntu/xorg-server@2:1.15.1-0ubuntu2.9?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
