Lucene search

K
suseSuseSUSE-SA:2005:056
HistorySep 26, 2005 - 1:04 p.m.

remote command execution in XFree86-server,xorg-x11-server

2005-09-2613:04:19
lists.opensuse.org
17

EPSS

0.026

Percentile

90.5%

The X server memory can be accessed my a malicious X client by exploiting a missing range check in the function XCreatePixmap(). This bug can probably be used to execute arbitrary code with the privileges of the X server (root).

Solution

There is no work-around known.