CVE-2015-0255
published 2015-02-13CVE-2015-0255: X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from process memory…
PriorityP429medium6.4CVSS 2.0
AVNACLAuNCPINAP
EPSS
4.50%
90.5th percentile
X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (crash) via a crafted string length value in a XkbSetGeometry request.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xorg-server | < xorg-server 2:1.16.4-1 (bookworm) | xorg-server 2:1.16.4-1 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| x.org | x_server | <= 1.16.3 | — |
| x.org | x_server | — | — |
| x.org | xorg-server | >= 0 < 2:1.16.4-1 | 2:1.16.4-1 |
| x.org | xorg-server | >= 0 < 2:1.16.4-1 | 2:1.16.4-1 |
| x.org | xorg-server | >= 0 < 2:1.16.4-1 | 2:1.16.4-1 |
| x.org | xorg-server | >= 0 < 2:1.16.4-1 | 2:1.16.4-1 |
| x.org | xorg-server | >= 0 < 2:1.15.1-0ubuntu2.7 | 2:1.15.1-0ubuntu2.7 |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
vendor_ubuntu6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qf46-p69c-vqm4: X
ghsa_unreviewed·2022-05-14
CVE-2015-0255 [MEDIUM] CWE-200 GHSA-qf46-p69c-vqm4: X
X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (crash) via a crafted string length value in a XkbSetGeometry request.
OSV
vnc4 vulnerabilities
osv·2021-03-15·CVSS 6.4
CVE-2015-0255 [MEDIUM] vnc4 vulnerabilities
vnc4 vulnerabilities
USN-2500-1 addressed CVE-2015-0255 for xorg-server. This update provides
the corresponding fix for VNC4 on Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
(CVE-2015-0255)
USN-2726-1 addressed CVE-2015-1283 for Expat. This update provides the
corresponding fix for VNC4 on Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
(CVE-2015-1283)
Original advisory details:
Olivier Fourdan discovered that the X.Org X server incorrectly handled
XkbSetGeometry requests resulting in an information leak. An attacker able
to connect to an X server, either locally or remotely, could use this issue
to possibly obtain sensitive information. (CVE-2015-0255)
It was discovered that Expat incorrectly handled malformed XML data. If a
user or application linked against Expat were tricked into opening a
crafte
OSV
xorg-server, xorg-server-lts-trusty, xorg-server-lts-utopic vulnerabilities
osv·2015-02-17·CVSS 5.0
CVE-2015-0255 [MEDIUM] xorg-server, xorg-server-lts-trusty, xorg-server-lts-utopic vulnerabilities
xorg-server, xorg-server-lts-trusty, xorg-server-lts-utopic vulnerabilities
Olivier Fourdan discovered that the X.Org X server incorrectly handled
XkbSetGeometry requests resulting in an information leak. An attacker able
to connect to an X server, either locally or remotely, could use this issue
to possibly obtain sensitive information. (CVE-2015-0255)
It was discovered that the X.Org X server incorrectly handled certain
trapezoids. An attacker able to connect to an X server, either locally or
remotely, could use this issue to possibly crash the server. This issue
only affected Ubuntu 12.04 LTS. (CVE-2013-6424)
OSV
CVE-2015-0255: X
osv·2015-02-13·CVSS 6.4
CVE-2015-0255 [MEDIUM] CVE-2015-0255: X
X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (crash) via a crafted string length value in a XkbSetGeometry request.
Ubuntu
VNC4 vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 6.4
CVE-2015-0255 [MEDIUM] VNC4 vulnerabilities
Title: VNC4 vulnerabilities
Summary: Several security issues were fixed in VNC4.
USN-2500-1 addressed CVE-2015-0255 for xorg-server. This update provides
the corresponding fix for VNC4 on Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
(CVE-2015-0255)
USN-2726-1 addressed CVE-2015-1283 for Expat. This update provides the
corresponding fix for VNC4 on Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
(CVE-2015-1283)
Original advisory details:
Olivier Fourdan discovered that the X.Org X server incorrectly handled
XkbSetGeometry requests resulting in an information leak. An attacker able
to connect to an X server, either locally or remotely, could use this issue
to possibly obtain sensitive information. (CVE-2015-0255)
It was discovered that Expat incorrectly handled malformed XML data. If a
user or applic
Ubuntu
X.Org X server vulnerabilities
vendor_ubuntu·2015-02-17·CVSS 5.0
CVE-2013-6424 [MEDIUM] X.Org X server vulnerabilities
Title: X.Org X server vulnerabilities
Summary: Several security issues were fixed in the X.Org X server.
Olivier Fourdan discovered that the X.Org X server incorrectly handled
XkbSetGeometry requests resulting in an information leak. An attacker able
to connect to an X server, either locally or remotely, could use this issue
to possibly obtain sensitive information. (CVE-2015-0255)
It was discovered that the X.Org X server incorrectly handled certain
trapezoids. An attacker able to connect to an X server, either locally or
remotely, could use this issue to possibly crash the server. This issue
only affected Ubuntu 12.04 LTS. (CVE-2013-6424)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
xorg-x11-server: information leak in the XkbSetGeometry request of X servers
vendor_redhat·2015-02-10·CVSS 6.4
CVE-2015-0255 [MEDIUM] CWE-125 xorg-x11-server: information leak in the XkbSetGeometry request of X servers
xorg-x11-server: information leak in the XkbSetGeometry request of X servers
X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (crash) via a crafted string length value in a XkbSetGeometry request.
A buffer overflow flaw was found in the way the X.Org server handled XkbGetGeometry requests. A malicious, authorized client could use this flaw to disclose portions of the X.Org server memory, or cause the X.Org server to crash using a specially crafted XkbGetGeometry request.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not current
Debian
CVE-2015-0255: xorg-server - X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17....
vendor_debian·2015·CVSS 6.4
CVE-2015-0255 [MEDIUM] CVE-2015-0255: xorg-server - X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17....
X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (crash) via a crafted string length value in a XkbSetGeometry request.
Scope: local
bookworm: resolved (fixed in 2:1.16.4-1)
bullseye: resolved (fixed in 2:1.16.4-1)
forky: resolved (fixed in 2:1.16.4-1)
sid: resolved (fixed in 2:1.16.4-1)
trixie: resolved (fixed in 2:1.16.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-0255 xorg-x11-server: information leak in the XkbSetGeometry request of X servers [fedora-all]
bugzilla·2015-02-17·CVSS 6.4
CVE-2015-0255 [MEDIUM] CVE-2015-0255 xorg-x11-server: information leak in the XkbSetGeometry request of X servers [fedora-all]
CVE-2015-0255 xorg-x11-server: information leak in the XkbSetGeometry request of X servers [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2015-0255 xorg-x11-server: information leak in the XkbSetGeometry request of X servers
bugzilla·2015-02-04·CVSS 6.4
CVE-2015-0255 [MEDIUM] CVE-2015-0255 xorg-x11-server: information leak in the XkbSetGeometry request of X servers
CVE-2015-0255 xorg-x11-server: information leak in the XkbSetGeometry request of X servers
Olivier Fourdan from Red Hat has discovered a protocol handling issue in the way the X server code base handles the XkbSetGeometry request.
The issue stems from the server trusting the client to send valid string lengths in the request data. A malicious client with string lengths exceeding the request length can cause the server to copy adjacent memory data into the XKB structs. This data is then available to the client via the XkbGetGeometry request.
The data length is at least up to 64k, it is possible to obtain more data by chaining strings, each string length is then determined by whatever happens to be in that 16-bit region of memory.
A similarly crafted request can likely cause the X server
http://advisories.mageia.org/MGASA-2015-0073.htmlhttp://lists.opensuse.org/opensuse-updates/2015-02/msg00085.htmlhttp://lists.opensuse.org/opensuse-updates/2015-02/msg00086.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0797.htmlhttp://www.debian.org/security/2015/dsa-3160http://www.mandriva.com/security/advisories?name=MDVSA-2015:119http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/72578http://www.ubuntu.com/usn/USN-2500-1http://www.x.org/wiki/Development/Security/Advisory-2015-02-10/https://security.gentoo.org/glsa/201504-06http://advisories.mageia.org/MGASA-2015-0073.htmlhttp://lists.opensuse.org/opensuse-updates/2015-02/msg00085.htmlhttp://lists.opensuse.org/opensuse-updates/2015-02/msg00086.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0797.htmlhttp://www.debian.org/security/2015/dsa-3160http://www.mandriva.com/security/advisories?name=MDVSA-2015:119http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/72578http://www.ubuntu.com/usn/USN-2500-1http://www.x.org/wiki/Development/Security/Advisory-2015-02-10/https://security.gentoo.org/glsa/201504-06
2015-02-13
Published