vendor:
X Server
by:
Marcelo Vázquez (aka s4vitar)
7.8
CVSS
HIGH
Stack Overflow
119
CWE
Product Name: X Server
Affected Version From: 1.20.4
Affected Version To: 1.20.4
Patch Exists: YES
Related CWE: CVE-2019-17624
CPE: a:xorg:x_server
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2019
X.Org X Server 1.20.4 – Local Stack Overflow
X.Org X Server 1.20.4 is vulnerable to a local stack overflow vulnerability. The vulnerability is caused due to a boundary error within the XQueryKeymap() function when handling user-supplied input. This can be exploited to cause a stack-based buffer overflow by sending a specially crafted request to the affected server.
Mitigation:
Upgrade to X.Org X Server version 1.20.5 or later.