CVE-2018-15855 — NULL Pointer Dereference in Project Xkbcommon
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 86.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 25
Latest updateMay 14
Description
Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because the XkbFile for an xkb_geometry section was mishandled.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages4 packages
Also affects: Ubuntu Linux 14.04, 16.04, 18.04
Patches
🔴Vulnerability Details
4📋Vendor Advisories
4Debian▶
CVE-2018-15855: libxkbcommon - Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local at...↗2018
💬Community
1Bugzilla
▶