Vulnerability Name: | CVE-2012-1699 (CCN-80789) | ||||||||||||
Assigned: | 2012-07-24 | ||||||||||||
Published: | 2012-07-24 | ||||||||||||
Updated: | 2017-09-19 | ||||||||||||
Summary: | The ProcSetEventMask function in difs/events.c in the xfs font server for X.Org X11R6 through X11R6.6 and XFree86 before 3.3.3 calls the SendErrToClient function with a mask value instead of a pointer, which allows local users to cause a denial of service (memory corruption and crash) or obtain potentially sensitive information from memory via a SetEventMask request that triggers an invalid pointer dereference. | ||||||||||||
CVSS v3 Severity: | 5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)
| ||||||||||||
CVSS v2 Severity: | 3.6 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:P) 2.6 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:P/E:U/RL:OF/RC:C)
2.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2012-1699 Source: MISC Type: UNKNOWN http://invisible-island.net/ansification/ansify-xfs-cve.html Source: MLIST Type: UNKNOWN [xorg-announce] 20120724 X.Org security advisory: DoS/info leak in xfs prior to X11R6.7/XFree86 3.3.3 Source: HP Type: UNKNOWN SSRT100883 Source: MISC Type: UNKNOWN http://twitter.com/bsdaemon/status/228958599790071809 Source: CCN Type: BID-57047 X11 and XFree86 CVE-2012-1699 Local Information Disclosure and Denial of Service Vulnerability Source: CCN Type: X.Org Foundation Web site X.Org Wiki - Home Source: CONFIRM Type: UNKNOWN https://blogs.oracle.com/sunsecurity/entry/cve_2012_1699_denial_of Source: CCN Type: Red Hat Bugzilla Bug 842841 CVE-2012-1699 xorg-x11: DoS and information leak in xfs prior to X11R6.7 Source: MISC Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=842841 Source: XF Type: UNKNOWN xorg-procseteventmask-dos(80789) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:19369 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |