Wind River Support Network

HomeDefectsLIN6-14836
Fixed

LIN6-14836 : Security Advisory - xorg-x11-server - CVE-2017-2624

Created: Aug 1, 2018    Updated: Dec 16, 2018
Resolved Date: Nov 18, 2018
Found In Version: 6.0.0.37
Fix Version: 6.0.0.38
Severity: Standard
Applicable for: Wind River Linux 6
Component/s: Userspace

Description

It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is seen, this causes a time difference between a valid and invalid byte, which could allow an efficient brute force attack.

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2624

Other Downloads


Live chat
Online