CVE-2017-2624

EUVD-2017-11785
It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is seen, this causes a time difference between a valid and invalid byte, which could allow an efficient brute force attack.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
redhatCNA
5.9 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 14%
Affected Products (NVD)
VendorProductVersion
x.orgx_server
𝑥
≤ 1.19.4
debiandebian_linux
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
xorg-server
bookworm
2:21.1.7-3+deb12u7
fixed
bookworm (security)
2:21.1.7-3+deb12u8
fixed
bullseye
2:1.20.11-1+deb11u13
fixed
bullseye (security)
2:1.20.11-1+deb11u14
fixed
sid
2:21.1.14-1
fixed
trixie
2:21.1.14-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
xorg-server
precise
ignored
trusty
Fixed 2:1.15.1-0ubuntu2.9
released
xenial
Fixed 2:1.18.4-0ubuntu0.3
released
yakkety
ignored
zesty
not-affected
xorg-server-hwe-16.04
precise
dne
trusty
dne
xenial
Fixed 2:1.18.4-1ubuntu6.1~16.04.2
released
yakkety
dne
zesty
dne
xorg-server-lts-quantal
precise
ignored
trusty
dne
xenial
dne
yakkety
dne
zesty
dne
xorg-server-lts-raring
precise
ignored
trusty
dne
xenial
dne
yakkety
dne
zesty
dne
xorg-server-lts-saucy
precise
ignored
trusty
dne
xenial
dne
yakkety
dne
zesty
dne
xorg-server-lts-trusty
precise
ignored
trusty
dne
xenial
dne
yakkety
dne
zesty
dne
xorg-server-lts-utopic
precise
dne
trusty
dne
xenial
dne
yakkety
dne
zesty
dne
xorg-server-lts-vivid
precise
dne
trusty
dne
xenial
dne
yakkety
dne
zesty
dne
xorg-server-lts-wily
precise
dne
trusty
dne
xenial
dne
yakkety
dne
zesty
dne
xorg-server-lts-xenial
precise
dne
trusty
Fixed 2:1.18.3-1ubuntu2.3~trusty2
released
xenial
dne
yakkety
dne
zesty
dne