It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is seen, this causes a time difference between a valid and invalid byte, which could allow an efficient brute force attack.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "xdmx", "binary_version": "2:1.15.1-0ubuntu2.9" }, { "binary_name": "xdmx-dbgsym", "binary_version": "2:1.15.1-0ubuntu2.9" }, { "binary_name": "xdmx-tools", "binary_version": "2:1.15.1-0ubuntu2.9" }, { "binary_name": "xdmx-tools-dbgsym", "binary_version": "2:1.15.1-0ubuntu2.9" }, { "binary_name": "xnest", "binary_version": "2:1.15.1-0ubuntu2.9" }, { "binary_name": "xnest-dbgsym", "binary_version": "2:1.15.1-0ubuntu2.9" }, { "binary_name": "xorg-server-source", "binary_version": "2:1.15.1-0ubuntu2.9" }, { "binary_name": "xserver-common", "binary_version": "2:1.15.1-0ubuntu2.9" }, { "binary_name": "xserver-xephyr", "binary_version": "2:1.15.1-0ubuntu2.9" }, { "binary_name": "xserver-xephyr-dbgsym", "binary_version": "2:1.15.1-0ubuntu2.9" }, { "binary_name": "xserver-xorg-core", "binary_version": "2:1.15.1-0ubuntu2.9" }, { "binary_name": "xserver-xorg-core-dbg", "binary_version": "2:1.15.1-0ubuntu2.9" }, { "binary_name": "xserver-xorg-core-dbgsym", "binary_version": "2:1.15.1-0ubuntu2.9" }, { "binary_name": "xserver-xorg-core-udeb", "binary_version": "2:1.15.1-0ubuntu2.9" }, { "binary_name": "xserver-xorg-core-udeb-dbgsym", "binary_version": "2:1.15.1-0ubuntu2.9" }, { "binary_name": "xserver-xorg-dev", "binary_version": "2:1.15.1-0ubuntu2.9" }, { "binary_name": "xserver-xorg-dev-dbgsym", "binary_version": "2:1.15.1-0ubuntu2.9" }, { "binary_name": "xserver-xorg-xmir", "binary_version": "2:1.15.1-0ubuntu2.9" }, { "binary_name": "xserver-xorg-xmir-dbgsym", "binary_version": "2:1.15.1-0ubuntu2.9" }, { "binary_name": "xvfb", "binary_version": "2:1.15.1-0ubuntu2.9" }, { "binary_name": "xvfb-dbgsym", "binary_version": "2:1.15.1-0ubuntu2.9" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "xorg-server-source-lts-xenial", "binary_version": "2:1.18.3-1ubuntu2.3~trusty2" }, { "binary_name": "xserver-xephyr-lts-xenial", "binary_version": "2:1.18.3-1ubuntu2.3~trusty2" }, { "binary_name": "xserver-xephyr-lts-xenial-dbgsym", "binary_version": "2:1.18.3-1ubuntu2.3~trusty2" }, { "binary_name": "xserver-xorg-core-lts-xenial", "binary_version": "2:1.18.3-1ubuntu2.3~trusty2" }, { "binary_name": "xserver-xorg-core-lts-xenial-dbg", "binary_version": "2:1.18.3-1ubuntu2.3~trusty2" }, { "binary_name": "xserver-xorg-core-lts-xenial-dbgsym", "binary_version": "2:1.18.3-1ubuntu2.3~trusty2" }, { "binary_name": "xserver-xorg-dev-lts-xenial", "binary_version": "2:1.18.3-1ubuntu2.3~trusty2" }, { "binary_name": "xwayland-lts-xenial", "binary_version": "2:1.18.3-1ubuntu2.3~trusty2" }, { "binary_name": "xwayland-lts-xenial-dbgsym", "binary_version": "2:1.18.3-1ubuntu2.3~trusty2" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "xdmx", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xdmx-dbgsym", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xdmx-tools", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xdmx-tools-dbgsym", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xmir", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xmir-dbgsym", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xnest", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xnest-dbgsym", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xorg-server-source", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xserver-common", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xserver-xephyr", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xserver-xephyr-dbgsym", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xserver-xorg-core", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xserver-xorg-core-dbg", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xserver-xorg-core-dbgsym", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xserver-xorg-core-udeb", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xserver-xorg-core-udeb-dbgsym", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xserver-xorg-dev", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xserver-xorg-legacy", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xserver-xorg-legacy-dbgsym", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xserver-xorg-xmir", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xvfb", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xvfb-dbgsym", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xwayland", "binary_version": "2:1.18.4-0ubuntu0.3" }, { "binary_name": "xwayland-dbgsym", "binary_version": "2:1.18.4-0ubuntu0.3" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "xmir-hwe-16.04", "binary_version": "2:1.18.4-1ubuntu6.1~16.04.2" }, { "binary_name": "xmir-hwe-16.04-dbgsym", "binary_version": "2:1.18.4-1ubuntu6.1~16.04.2" }, { "binary_name": "xorg-server-source-hwe-16.04", "binary_version": "2:1.18.4-1ubuntu6.1~16.04.2" }, { "binary_name": "xserver-xephyr-hwe-16.04", "binary_version": "2:1.18.4-1ubuntu6.1~16.04.2" }, { "binary_name": "xserver-xephyr-hwe-16.04-dbgsym", "binary_version": "2:1.18.4-1ubuntu6.1~16.04.2" }, { "binary_name": "xserver-xorg-core-hwe-16.04", "binary_version": "2:1.18.4-1ubuntu6.1~16.04.2" }, { "binary_name": "xserver-xorg-core-hwe-16.04-dbg", "binary_version": "2:1.18.4-1ubuntu6.1~16.04.2" }, { "binary_name": "xserver-xorg-core-hwe-16.04-dbgsym", "binary_version": "2:1.18.4-1ubuntu6.1~16.04.2" }, { "binary_name": "xserver-xorg-dev-hwe-16.04", "binary_version": "2:1.18.4-1ubuntu6.1~16.04.2" }, { "binary_name": "xserver-xorg-legacy-hwe-16.04", "binary_version": "2:1.18.4-1ubuntu6.1~16.04.2" }, { "binary_name": "xserver-xorg-legacy-hwe-16.04-dbgsym", "binary_version": "2:1.18.4-1ubuntu6.1~16.04.2" }, { "binary_name": "xwayland-hwe-16.04", "binary_version": "2:1.18.4-1ubuntu6.1~16.04.2" }, { "binary_name": "xwayland-hwe-16.04-dbgsym", "binary_version": "2:1.18.4-1ubuntu6.1~16.04.2" } ] }