Memory Information Disclosure and Denial of Service in X.Org Server
CVE-2015-0255

Currently unrated

Key Information:

Vendor

X.org

Vendor
CVE Published:
13 February 2015

What is CVE-2015-0255?

The X.Org Server is vulnerable to a potentially exploitable flaw that allows remote attackers to retrieve sensitive information from process memory or trigger a denial of service through a specially crafted string length value in an XkbSetGeometry request. This issue primarily affects versions prior to 1.16.3 and those in the 1.17.x series before 1.17.1. Security patches are available, and users are advised to update their installations promptly.

References

EPSS Score

8% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.