CVE-2015-3164
01.07.2015, 14:59
The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.Enginsight
| Vendor | Product | Version |
|---|---|---|
| opensuse | opensuse | 13.2 |
| x.org | x_server | 1.16.0 |
| x.org | x_server | 1.16.1 |
| x.org | x_server | 1.16.1.901 |
| x.org | x_server | 1.16.2 |
| x.org | x_server | 1.16.2.901 |
| x.org | x_server | 1.16.3 |
| x.org | x_server | 1.17.0 |
| x.org | xorg-server | 1.16.4 |
| x.org | xorg-server | 1.16.99.901 |
| x.org | xorg-server | 1.16.99.902 |
| x.org | xorg-server | 1.17.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| xorg-server |
| ||||||||||||||||
| xorg-server-lts-quantal |
| ||||||||||||||||
| xorg-server-lts-raring |
| ||||||||||||||||
| xorg-server-lts-saucy |
| ||||||||||||||||
| xorg-server-lts-trusty |
| ||||||||||||||||
| xorg-server-lts-utopic |
| ||||||||||||||||
| xorg-server-lts-vivid |
|
Common Weakness Enumeration
References