CVE-2019-17624

EUVD-2019-7940
"" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sending ct.c_char 1000 times, an attacker can cause a denial of service (application crash) or possibly have unspecified other impact. Note: It is disputed if the X.Org X Server is involved or if there is a stack overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
Affected Products (NVD)
VendorProductVersion
x.orgx_server
𝑥
≤ 1.20.4
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
xorg
bionic
not-affected
disco
not-affected
eoan
not-affected
focal
not-affected
trusty
dne
xenial
not-affected
xorg-hwe-16.04
bionic
dne
disco
dne
eoan
dne
focal
dne
trusty
dne
xenial
not-affected
xorg-server
bionic
not-affected
disco
ignored
eoan
ignored
focal
not-affected
trusty
not-affected
xenial
not-affected
xorg-server-hwe-16.04
bionic
dne
disco
dne
eoan
dne
focal
dne
trusty
dne
xenial
not-affected
xorg-server-hwe-18.04
bionic
not-affected
focal
dne
trusty
dne
xenial
dne
xorg-server-lts-utopic
bionic
dne
disco
dne
eoan
dne
focal
dne
trusty
dne
xenial
dne
xorg-server-lts-vivid
bionic
dne
disco
dne
eoan
dne
focal
dne
trusty
dne
xenial
dne
xorg-server-lts-wily
bionic
dne
disco
dne
eoan
dne
focal
dne
trusty
dne
xenial
dne
xorg-server-lts-xenial
bionic
dne
disco
dne
eoan
dne
focal
dne
trusty
dne
xenial
dne