vendor:
XFree86
by:
Chris Evans
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: XFree86
Affected Version From: 3.3.2005
Affected Version To: 4
Patch Exists: YES
Related CWE: N/A
CPE: XFree86
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Denial of Service in XFree86 3.3.5, 3.3.6 and 4.0
A denial of service exists in XFree86 3.3.5, 3.3.6 and 4.0. A remote user can send a malformed packet to the TCP listening port, 6000, which will cause the X server to be unresponsive for some period of time. During this time, the keyboard will not respond to user input, and in some cases, the mouse will also not respond. During this time period, the X server will utilize 100% of the CPU, and can only be repaired by being signaled. This vulnerability exists only in servers compiled with the XCSECURITY #define set.
Mitigation:
Compile XFree86 with XCSECURITY #define set.