The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xorg-server | Jul 30, 2024 | Jul 1, 2015 |
| Gentoo Linux | — | Upgrade x11-base/xorg-server. | Oct 30, 2017 | Jul 1, 2015 |
| Suse | — | Upgrade xorg-x11-serverUpgrade xorg-x11-server-waylandUpgrade xorg-x11-server-extraUpgrade xorg-x11-server-sdk | Dec 18, 2015 | Jun 22, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub