Wind River Support Network

HomeDefectsLIN9-7257
Fixed

LIN9-7257 : Security Advisory - xorg-x11-server - CVE-2017-2624

Created: Jul 31, 2018    Updated: Dec 3, 2018
Resolved Date: Aug 10, 2018
Found In Version: unknown
Fix Version: 9.0.0.18
Severity: Standard
Applicable for: Wind River Linux 9
Component/s: Userspace

Description

It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is seen, this causes a time difference between a valid and invalid byte, which could allow an efficient brute force attack.

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2624

Other Downloads


CVEs


Live chat
Online