CVE-2012-2118
published 2012-05-18CVE-2012-2118: Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibly execute…
PriorityP337critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.69%
84.3th percentile
Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibly execute arbitrary code via format string specifiers in an input device name.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:1.12.1.902-1 (bookworm) | xorg-server 2:1.12.1.902-1 (bookworm) |
| x.org | x11 | — | — |
| x.org | xorg-server | >= 0 < 2:1.12.1.902-1 | 2:1.12.1.902-1 |
| x.org | xorg-server | >= 0 < 2:1.12.1.902-1 | 2:1.12.1.902-1 |
| x.org | xorg-server | >= 0 < 2:1.12.1.902-1 | 2:1.12.1.902-1 |
| x.org | xorg-server | >= 0 < 2:1.12.1.902-1 | 2:1.12.1.902-1 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wqgf-h892-f3cp: Format string vulnerability in the LogVHdrMessageVerb function in os/log
ghsa_unreviewed·2022-05-17
CVE-2012-2118 [HIGH] CWE-20 GHSA-wqgf-h892-f3cp: Format string vulnerability in the LogVHdrMessageVerb function in os/log
Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibly execute arbitrary code via format string specifiers in an input device name.
OSV
CVE-2012-2118: Format string vulnerability in the LogVHdrMessageVerb function in os/log
osv·2012-05-18·CVSS 10.0
CVE-2012-2118 [CRITICAL] CVE-2012-2118: Format string vulnerability in the LogVHdrMessageVerb function in os/log
Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibly execute arbitrary code via format string specifiers in an input device name.
Ubuntu
X.Org X Server vulnerability
vendor_ubuntu·2012-07-11
CVE-2012-2118 X.Org X Server vulnerability
Title: X.Org X Server vulnerability
Summary: The X.Org X server could be made to crash if a specially crafted input
device was added.
Ken Mixter discovered a format string vulnerability in the
LogVHdrMessageVerb function when handling input device names. This
could allow a local attacker to cause a denial of service or possibly
execute arbitrary code.
The default compiler options for the affected release should reduce
the vulnerability to a denial of service.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
xorg-x11-server: Input device name logging format string flaw
vendor_redhat·2012-04-18·CVSS 10.0
CVE-2012-2118 [CRITICAL] xorg-x11-server: Input device name logging format string flaw
xorg-x11-server: Input device name logging format string flaw
Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibly execute arbitrary code via format string specifiers in an input device name.
Statement: Red Hat does not consider crash of end user application such as xorg-x11-server caused by local user actions to be a security flaw.
Package: xorg-x11-server (Red Hat Enterprise Linux 5) - Not affected
Package: xorg-x11-server (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2012-2118: xorg-server - Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X....
vendor_debian·2012·CVSS 10.0
CVE-2012-2118 [CRITICAL] CVE-2012-2118: xorg-server - Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X....
Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibly execute arbitrary code via format string specifiers in an input device name.
Scope: local
bookworm: resolved (fixed in 2:1.12.1.902-1)
bullseye: resolved (fixed in 2:1.12.1.902-1)
forky: resolved (fixed in 2:1.12.1.902-1)
sid: resolved (fixed in 2:1.12.1.902-1)
trixie: resolved (fixed in 2:1.12.1.902-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2118 xorg-x11-server: Input device name logging format string flaw
bugzilla·2012-04-19·CVSS 10.0
CVE-2012-2118 [CRITICAL] CVE-2012-2118 xorg-x11-server: Input device name logging format string flaw
CVE-2012-2118 xorg-x11-server: Input device name logging format string flaw
A format string flaw was found in the way xorg-x11-server, a X.Org X11 X server, performed log message writes for certain forms of the log message to be written. If a local attacker assigned a specially-crafted name to a input device and was able to trick the system administrator in order to the local Xorg server instance to use this device, it would lead to Xorg service instance abort.
Upstream patch series:
[1] http://patchwork.freedesktop.org/patch/10000/
[2] http://patchwork.freedesktop.org/patch/9998/
[3] http://patchwork.freedesktop.org/patch/9999/
[4] http://patchwork.freedesktop.org/patch/10001/
CVE request:
[5] http://www.openwall.com/lists/oss-security/2012/04/18/8
CVE assignment:
[6] http://www.openw
Bugzilla
CVE-2012-2118 xorg-x11-server: Input device name logging format string flaw [fedora-all]
bugzilla·2012-04-19·CVSS 10.0
CVE-2012-2118 [CRITICAL] CVE-2012-2118 xorg-x11-server: Input device name logging format string flaw [fedora-all]
CVE-2012-2118 xorg-x11-server: Input device name logging format string flaw [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?t
http://patchwork.freedesktop.org/patch/10001/http://www.openwall.com/lists/oss-security/2012/04/18/8http://www.openwall.com/lists/oss-security/2012/04/19/2http://www.securityfocus.com/bid/53150https://exchange.xforce.ibmcloud.com/vulnerabilities/74930http://patchwork.freedesktop.org/patch/10001/http://www.openwall.com/lists/oss-security/2012/04/18/8http://www.openwall.com/lists/oss-security/2012/04/19/2http://www.securityfocus.com/bid/53150https://exchange.xforce.ibmcloud.com/vulnerabilities/74930
2012-05-18
Published