CVE-2017-12176

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/01/2018
Last modified:
29/08/2025

Description

xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:x.org:x_server:*:*:*:*:*:*:*:* 1.19.5 (excluding)