Описание
Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap file that triggers boolean negation.
An uncontrolled recursion flaw was found in libxkbcommon in the way it parses boolean expressions. A specially crafted file provided to xkbcomp could crash the application.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 8 | libxkbcommon | Not affected | ||
| Red Hat Enterprise Linux 7 | gdm | Fixed | RHSA-2019:2079 | 06.08.2019 |
| Red Hat Enterprise Linux 7 | libX11 | Fixed | RHSA-2019:2079 | 06.08.2019 |
| Red Hat Enterprise Linux 7 | libxkbcommon | Fixed | RHSA-2019:2079 | 06.08.2019 |
| Red Hat Enterprise Linux 7 | mesa-libGLw | Fixed | RHSA-2019:2079 | 06.08.2019 |
| Red Hat Enterprise Linux 7 | xorg-x11-drv-ati | Fixed | RHSA-2019:2079 | 06.08.2019 |
| Red Hat Enterprise Linux 7 | xorg-x11-drv-vesa | Fixed | RHSA-2019:2079 | 06.08.2019 |
| Red Hat Enterprise Linux 7 | xorg-x11-drv-wacom | Fixed | RHSA-2019:2079 | 06.08.2019 |
| Red Hat Enterprise Linux 7 | xorg-x11-server | Fixed | RHSA-2019:2079 | 06.08.2019 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.3 Low
CVSS3
Связанные уязвимости
Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap file that triggers boolean negation.
Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap file that triggers boolean negation.
Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcomm ...
Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap file that triggers boolean negation.
EPSS
3.3 Low
CVSS3