Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-2624

Опубликовано: 27 июл. 2018
Источник: debian

Описание

It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is seen, this causes a time difference between a valid and invalid byte, which could allow an efficient brute force attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xorg-serverfixed2:1.19.2-1package
xorg-serverfixed2:1.16.4-1+deb8u2jessiepackage

Примечания

  • https://www.x41-dsec.de/lab/advisories/x41-2017-001-xorg/

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 7 лет назад

It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is seen, this causes a time difference between a valid and invalid byte, which could allow an efficient brute force attack.

CVSS3: 5.9
redhat
почти 9 лет назад

It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is seen, this causes a time difference between a valid and invalid byte, which could allow an efficient brute force attack.

CVSS3: 5.9
nvd
больше 7 лет назад

It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is seen, this causes a time difference between a valid and invalid byte, which could allow an efficient brute force attack.

suse-cvrf
больше 8 лет назад

Security update for xorg-x11-server

suse-cvrf
больше 8 лет назад

Security update for xorg-x11-server