Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-3164

Опубликовано: 01 июл. 2015
Источник: debian
EPSS Низкий

Описание

The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xorg-serverfixed2:1.17.2-1package
xorg-serverfixed2:1.16.4-1+deb8u2jessiepackage
xorg-servernot-affectedwheezypackage
xorg-servernot-affectedsqueezepackage

Примечания

  • http://lists.freedesktop.org/archives/wayland-devel/2015-June/022548.html

  • Patch 1/3: http://cgit.freedesktop.org/xorg/xserver/commit/?id=c4534a38b68aa07fb82318040dc8154fb48a9588

  • Patch 2/3: http://cgit.freedesktop.org/xorg/xserver/commit/?id=4b4b9086d02b80549981d205fb1f495edc373538

  • Patch 3/3: http://cgit.freedesktop.org/xorg/xserver/commit/?id=76636ac12f2d1dbdf7be08222f80e7505d53c451

EPSS

Процентиль: 20%
0.00065
Низкий

Связанные уязвимости

ubuntu
больше 10 лет назад

The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.

redhat
больше 10 лет назад

The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.

nvd
больше 10 лет назад

The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.

github
больше 3 лет назад

The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.

EPSS

Процентиль: 20%
0.00065
Низкий