Wind River Support Network

HomeDefectsLIN8-9578
Fixed

LIN8-9578 : Security Advisory - xorg-x11-server - CVE-2017-2624

Created: Jul 31, 2018    Updated: Dec 3, 2018
Resolved Date: Aug 5, 2018
Found In Version: 8.0
Fix Version: 8.0.0.27
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is seen, this causes a time difference between a valid and invalid byte, which could allow an efficient brute force attack.

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2624

Other Downloads


CVEs


Live chat
Online