Back

LOW

xorg-x11: DoS and information leak in xfs prior to X11R6.7

Published Dec 21, 2012

Description

The ProcSetEventMask function in difs/events.c in the xfs font server for X.Org X11R6 through X11R6.6 and XFree86 before 3.3.3 calls the SendErrToClient function with a mask value instead of a pointer, which allows local users to cause a denial of service (memory corruption and crash) or obtain potentially sensitive information from memory via a SetEventMask request that triggers an invalid pointer dereference.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of xorg-x11-xfs as shipped with Red Hat Enterprise Linux 5. It does not affect Red Hat Enterprise Linux 6 as it no longer uses or provides the XFS font server.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner oracle
Published Dec 21, 2012
Updated Aug 6, 2024
Reserved Mar 16, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Jul 24, 2012