CVE-2017-2624

It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is seen, this causes a time difference between a valid and invalid byte, which could allow an efficient brute force attack.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 14%
Affected Products (NVD)
VendorProductVersion
x.orgx_server
𝑥
≤ 1.19.4
debiandebian_linux
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
xorg-server
bookworm
2:21.1.7-3+deb12u7
fixed
bookworm (security)
2:21.1.7-3+deb12u8
fixed
bullseye
2:1.20.11-1+deb11u13
fixed
bullseye (security)
2:1.20.11-1+deb11u14
fixed
sid
2:21.1.14-1
fixed
trixie
2:21.1.14-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
xorg-server
precise
ignored
trusty
Fixed 2:1.15.1-0ubuntu2.9
released
xenial
Fixed 2:1.18.4-0ubuntu0.3
released
yakkety
ignored
zesty
not-affected
xorg-server-hwe-16.04
precise
dne
trusty
dne
xenial
Fixed 2:1.18.4-1ubuntu6.1~16.04.2
released
yakkety
dne
zesty
dne
xorg-server-lts-quantal
precise
ignored
trusty
dne
xenial
dne
yakkety
dne
zesty
dne
xorg-server-lts-raring
precise
ignored
trusty
dne
xenial
dne
yakkety
dne
zesty
dne
xorg-server-lts-saucy
precise
ignored
trusty
dne
xenial
dne
yakkety
dne
zesty
dne
xorg-server-lts-trusty
precise
ignored
trusty
dne
xenial
dne
yakkety
dne
zesty
dne
xorg-server-lts-utopic
precise
dne
trusty
dne
xenial
dne
yakkety
dne
zesty
dne
xorg-server-lts-vivid
precise
dne
trusty
dne
xenial
dne
yakkety
dne
zesty
dne
xorg-server-lts-wily
precise
dne
trusty
dne
xenial
dne
yakkety
dne
zesty
dne
xorg-server-lts-xenial
precise
dne
trusty
Fixed 2:1.18.3-1ubuntu2.3~trusty2
released
xenial
dne
yakkety
dne
zesty
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
xorg-x11-server
suse enterprise desktop 15
1.19.6-6.19
fixed
suse enterprise desktop 15 SP1
1.20.3-12.29
fixed
suse enterprise desktop 15 SP2
1.20.3-20.11
fixed
suse enterprise desktop 15 SP3
1.20.3-22.5.30.1
fixed
suse enterprise desktop 15 SP4
1.20.3-150400.36.7
fixed
suse enterprise desktop 15 SP5
21.1.4-150500.5.1
fixed
suse enterprise desktop 15 SP6
21.1.11-150600.3.2
fixed
suse enterprise desktop 15 SP7
21.1.15-150700.3.2
fixed
suse enterprise sap 12 SP5
1.19.6-8.18
fixed
suse enterprise sap 15
1.19.6-6.19
fixed
suse enterprise sap 15 SP1
1.20.3-12.29
fixed
suse enterprise sap 15 SP2
1.20.3-20.11
fixed
suse enterprise sap 15 SP3
1.20.3-22.5.30.1
fixed
suse enterprise sap 15 SP4
1.20.3-150400.36.7
fixed
suse enterprise sap 15 SP5
21.1.4-150500.5.1
fixed
suse enterprise sap 15 SP6
21.1.11-150600.3.2
fixed
suse enterprise sap 15 SP7
21.1.15-150700.3.2
fixed
suse enterprise server 12 SP5
1.19.6-8.18
fixed
suse enterprise server 15
1.19.6-6.19
fixed
suse enterprise server 15 SP1
1.20.3-12.29
fixed
suse enterprise server 15 SP2
1.20.3-20.11
fixed
suse enterprise server 15 SP3
1.20.3-22.5.30.1
fixed
suse enterprise server 15 SP4
1.20.3-150400.36.7
fixed
suse enterprise server 15 SP5
21.1.4-150500.5.1
fixed
suse enterprise server 15 SP6
21.1.11-150600.3.2
fixed
suse enterprise server 15 SP7
21.1.15-150700.3.2
fixed
xorg-x11-server-Xvfb
suse enterprise desktop 15 SP5
21.1.4-150500.5.1
fixed
suse enterprise desktop 15 SP6
21.1.11-150600.3.2
fixed
suse enterprise desktop 15 SP7
21.1.15-150700.3.2
fixed
suse enterprise sap 15 SP5
21.1.4-150500.5.1
fixed
suse enterprise sap 15 SP6
21.1.11-150600.3.2
fixed
suse enterprise sap 15 SP7
21.1.15-150700.3.2
fixed
suse enterprise server 15 SP5
21.1.4-150500.5.1
fixed
suse enterprise server 15 SP6
21.1.11-150600.3.2
fixed
suse enterprise server 15 SP7
21.1.15-150700.3.2
fixed
xorg-x11-server-extra
suse enterprise desktop 15
1.19.6-6.19
fixed
suse enterprise desktop 15 SP1
1.20.3-12.29
fixed
suse enterprise desktop 15 SP2
1.20.3-20.11
fixed
suse enterprise desktop 15 SP3
1.20.3-22.5.30.1
fixed
suse enterprise desktop 15 SP4
1.20.3-150400.36.7
fixed
suse enterprise desktop 15 SP5
21.1.4-150500.5.1
fixed
suse enterprise desktop 15 SP6
21.1.11-150600.3.2
fixed
suse enterprise desktop 15 SP7
21.1.15-150700.3.2
fixed
suse enterprise sap 12 SP5
1.19.6-8.18
fixed
suse enterprise sap 15
1.19.6-6.19
fixed
suse enterprise sap 15 SP1
1.20.3-12.29
fixed
suse enterprise sap 15 SP2
1.20.3-20.11
fixed
suse enterprise sap 15 SP3
1.20.3-22.5.30.1
fixed
suse enterprise sap 15 SP4
1.20.3-150400.36.7
fixed
suse enterprise sap 15 SP5
21.1.4-150500.5.1
fixed
suse enterprise sap 15 SP6
21.1.11-150600.3.2
fixed
suse enterprise sap 15 SP7
21.1.15-150700.3.2
fixed
suse enterprise server 12 SP5
1.19.6-8.18
fixed
suse enterprise server 15
1.19.6-6.19
fixed
suse enterprise server 15 SP1
1.20.3-12.29
fixed
suse enterprise server 15 SP2
1.20.3-20.11
fixed
suse enterprise server 15 SP3
1.20.3-22.5.30.1
fixed
suse enterprise server 15 SP4
1.20.3-150400.36.7
fixed
suse enterprise server 15 SP5
21.1.4-150500.5.1
fixed
suse enterprise server 15 SP6
21.1.11-150600.3.2
fixed
suse enterprise server 15 SP7
21.1.15-150700.3.2
fixed