Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3164

Опубликовано: 10 июн. 2015
Источник: redhat
CVSS2: 5.1
EPSS Низкий

Описание

The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.

Отчет

Not vulnerable. This issue did not affect the versions of xorg-x11-server as shipped with Red Hat Enterprise Linux 5, 6, and 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5xorg-x11-serverNot affected
Red Hat Enterprise Linux 6xorg-x11-serverNot affected
Red Hat Enterprise Linux 7xorg-x11-serverNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1219548xorg-x11-server: Xwayland allows unconditional open access to display

EPSS

Процентиль: 20%
0.00065
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.

nvd
больше 10 лет назад

The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.

debian
больше 10 лет назад

The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 s ...

github
больше 3 лет назад

The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.

EPSS

Процентиль: 20%
0.00065
Низкий

5.1 Medium

CVSS2