It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is seen, this causes a time difference between a valid and invalid byte, which could allow an efficient brute force attack.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xorg-server | Feb 25, 2019 | Jul 27, 2018 |
| Gentoo Linux | — | Upgrade x11-libs/libXrandr.Upgrade x11-libs/libXv.Upgrade x11-libs/libXrender.Upgrade x11-libs/libXfixes.Upgrade x11-libs/libXi.Upgrade x11-libs/libICE.Upgrade x11-libs/libXdmcp.Upgrade x11-base/xorg-server. | Oct 30, 2017 | Apr 10, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade xorg-x11-server-common | Dec 4, 2019 | Jul 27, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade xorg-x11-server-common | Dec 18, 2019 | Jul 27, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 27, 2018 |
| Suse | — | Upgrade xorg-x11-server-waylandUpgrade xorg-x11-server-extraUpgrade xorg-x11-server-sdkUpgrade xorg-x11-XvncUpgrade xorg-x11-server | Jun 19, 2017 | Jun 19, 2017 |
| Ubuntu | — | Upgrade xserver-xorg-coreUpgrade xserver-xorg-core-hwe-16.04Upgrade xserver-xorg-core-lts-xenial | Jul 24, 2017 | Jun 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub