Out-of-bounds Write Affecting xorg-server package, versions [,21.1.4)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.76% (73rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-XORGSERVER-2429226
  • published26 Jan 2022
  • disclosed27 Dec 2013
  • creditUnknown

Introduced: 27 Dec 2013

CVE-2013-2179  (opens in a new tab)
CWE-787  (opens in a new tab)

How to fix?

Upgrade xorg-server to version 21.1.4 or higher.

Overview

Affected versions of this package are vulnerable to Out-of-bounds Write. X.Org xdm 1.1.10, 1.1.11, and possibly other versions, when performing authentication using certain implementations of the crypt API function that can return NULL, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by attempting to log into an account whose password field contains invalid characters, as demonstrated using the crypt function from glibc 2.17 and later with (1) the "!" character in the salt portion of a password field or (2) a password that has been encrypted using DES or MD5 in FIPS-140 mode.

CVSS Base Scores

version 3.1