Xorg X Server Vulnerability in Connection Handling by The X.Org Foundation
CVE-2017-12176
9.8CRITICAL
What is CVE-2017-12176?
The xorg-x11-server prior to version 1.19.5 lacks critical extra length validation in the ProcEstablishConnection function. This oversight can be exploited by a malicious X client, leading to potential crashes of the X server and, in some cases, the execution of arbitrary code. Users of affected versions should promptly apply the available security updates to mitigate potential risks.
Affected Version(s)
xorg-x11-server before 1.19.5