CVE-2015-0255

Public on 2015-02-13
Modified on 2015-05-05
Description
A buffer overflow flaw was found in the way the X.Org server handled XkbGetGeometry requests. A malicious, authorized client could use this flaw to disclose portions of the X.Org server memory, or cause the X.Org server to crash using a specially crafted XkbGetGeometry request.
Severity
Medium severity
Medium
CVSS v3 Base Score
3.6
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 xorg-x11-server 2015-05-05 ALAS-2015-519 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv2 3.6 AV:L/AC:L/Au:N/C:P/I:N/A:P
NVD CVSSv2 6.4 AV:N/AC:L/Au:N/C:P/I:N/A:P