CVE-2019-17624

"" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sending ct.c_char 1000 times, an attacker can cause a denial of service (application crash) or possibly have unspecified other impact. Note: It is disputed if the X.Org X Server is involved or if there is a stack overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
VendorProductVersion
x.orgx_server
𝑥
≤ 1.20.4
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
xorg
focal
not-affected
eoan
not-affected
disco
not-affected
bionic
not-affected
xenial
not-affected
trusty
dne
xorg-hwe-16.04
focal
dne
eoan
dne
disco
dne
bionic
dne
xenial
not-affected
trusty
dne
xorg-server
focal
not-affected
eoan
ignored
disco
ignored
bionic
not-affected
xenial
not-affected
trusty
not-affected
xorg-server-hwe-16.04
focal
dne
eoan
dne
disco
dne
bionic
dne
xenial
not-affected
trusty
dne
xorg-server-hwe-18.04
focal
dne
bionic
not-affected
xenial
dne
trusty
dne
xorg-server-lts-utopic
focal
dne
eoan
dne
disco
dne
bionic
dne
xenial
dne
trusty
dne
xorg-server-lts-vivid
focal
dne
eoan
dne
disco
dne
bionic
dne
xenial
dne
trusty
dne
xorg-server-lts-wily
focal
dne
eoan
dne
disco
dne
bionic
dne
xenial
dne
trusty
dne
xorg-server-lts-xenial
focal
dne
eoan
dne
disco
dne
bionic
dne
xenial
dne
trusty
dne