CVE-2012-2118Improper Input Validation in X11

Severity
10.0CRITICALNVD
EPSS
2.1%
top 15.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 18
Latest updateMay 17

Description

Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibly execute arbitrary code via format string specifiers in an input device name.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

Debianx.org/xorg-server< 2:1.12.1.902-1+3
NVDx.org/x111.11

Patches

🔴Vulnerability Details

3
GHSA
GHSA-wqgf-h892-f3cp: Format string vulnerability in the LogVHdrMessageVerb function in os/log2022-05-17
OSV
CVE-2012-2118: Format string vulnerability in the LogVHdrMessageVerb function in os/log2012-05-18
CVEList
CVE-2012-2118: Format string vulnerability in the LogVHdrMessageVerb function in os/log2012-05-18

📋Vendor Advisories

3
Ubuntu
X.Org X Server vulnerability2012-07-11
Red Hat
xorg-x11-server: Input device name logging format string flaw2012-04-18
Debian
CVE-2012-2118: xorg-server - Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X....2012

💬Community

2
Bugzilla
CVE-2012-2118 xorg-x11-server: Input device name logging format string flaw2012-04-19
Bugzilla
CVE-2012-2118 xorg-x11-server: Input device name logging format string flaw [fedora-all]2012-04-19
CVE-2012-2118 — Improper Input Validation in X.org X11 | cvebase