xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xorg-server | Aug 22, 2024 | Jan 24, 2018 |
| Debian | — | Upgrade xorg-server | Oct 18, 2017 | Oct 12, 2017 |
| Freebsd | — | Upgrade xorg-vfbserverUpgrade xorg-serverUpgrade xwaylandUpgrade xephyrUpgrade xorg-nestserverUpgrade xorg-dmx | Oct 13, 2017 | Oct 13, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade xorg-x11-server-common | Dec 4, 2019 | Jan 24, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade xorg-x11-server-common | Dec 18, 2019 | Jan 24, 2018 |
| Oracle Solaris | — | Upgrade x11/server/xvnc to version 1.7.1-0.175.3.36.0.2.1551 on Solaris 11.3Upgrade x11/server/xorg to version 1.14.5-0.175.3.36.0.2.1551 on Solaris 11.3Upgrade x11/server/xephyr to version 1.14.5-0.175.3.36.0.2.1551 on Solaris 11.3Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4Upgrade x11/server/xvfb to version 1.14.5-0.175.3.36.0.2.1551 on Solaris 11.3Upgrade x11/server/xdmx to version 1.14.5-0.175.3.36.0.2.1551 on Solaris 11.3 | Oct 19, 2018 | Jan 24, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 24, 2018 |
| Suse | — | Upgrade xorg-x11-server-extraUpgrade xorg-x11-serverUpgrade xorg-x11-server-sdkUpgrade xorg-x11-xvnc | Oct 20, 2017 | Oct 12, 2017 |
| Ubuntu | ubuntu-upgrade-xserver-xorg-coreubuntu-upgrade-xserver-xorg-core-hwe-16-04ubuntu-upgrade-xserver-xorg-core-lts-xenial | Oct 17, 2017 | Oct 12, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub