X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (crash) via a crafted string length value in a XkbSetGeometry request.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "xdmx",
"binary_version": "2:1.15.1-0ubuntu2.7"
},
{
"binary_name": "xdmx-tools",
"binary_version": "2:1.15.1-0ubuntu2.7"
},
{
"binary_name": "xnest",
"binary_version": "2:1.15.1-0ubuntu2.7"
},
{
"binary_name": "xorg-server-source",
"binary_version": "2:1.15.1-0ubuntu2.7"
},
{
"binary_name": "xserver-common",
"binary_version": "2:1.15.1-0ubuntu2.7"
},
{
"binary_name": "xserver-xephyr",
"binary_version": "2:1.15.1-0ubuntu2.7"
},
{
"binary_name": "xserver-xorg-core",
"binary_version": "2:1.15.1-0ubuntu2.7"
},
{
"binary_name": "xserver-xorg-dev",
"binary_version": "2:1.15.1-0ubuntu2.7"
},
{
"binary_name": "xserver-xorg-xmir",
"binary_version": "2:1.15.1-0ubuntu2.7"
},
{
"binary_name": "xvfb",
"binary_version": "2:1.15.1-0ubuntu2.7"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "xorg-server-source-lts-utopic",
"binary_version": "2:1.16.0-1ubuntu1.2~trusty2"
},
{
"binary_name": "xserver-xephyr-lts-utopic",
"binary_version": "2:1.16.0-1ubuntu1.2~trusty2"
},
{
"binary_name": "xserver-xorg-core-lts-utopic",
"binary_version": "2:1.16.0-1ubuntu1.2~trusty2"
},
{
"binary_name": "xserver-xorg-dev-lts-utopic",
"binary_version": "2:1.16.0-1ubuntu1.2~trusty2"
},
{
"binary_name": "xwayland-lts-utopic",
"binary_version": "2:1.16.0-1ubuntu1.2~trusty2"
}
]
}