Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.71566
Category:Gentoo Local Security Checks
Title:Gentoo Security Advisory GLSA 201207-04 (xorg-server)
Summary:The remote host is missing updates announced in;advisory GLSA 201207-04.
Description:Summary:
The remote host is missing updates announced in
advisory GLSA 201207-04.

Vulnerability Insight:
A format string vulnerability in X.Org X Server may allow local
privilege escalation or Denial of Service.

Solution:
All X.Org X Server 1.11.x users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose '>=x11-base/xorg-server-1.11.4-r1'


All X.Org X Server 1.10.x users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose '>=x11-base/xorg-server-1.10.6-r1'


X.Org X Server 1.9.x is not affected.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-2118
53150
http://www.securityfocus.com/bid/53150
[oss-security] 20120418 CVE request: Xorg input device format string flaw
http://www.openwall.com/lists/oss-security/2012/04/18/8
[oss-security] 20120418 Re: CVE request: Xorg input device format string flaw
http://www.openwall.com/lists/oss-security/2012/04/19/2
http://patchwork.freedesktop.org/patch/10001/
xorg-input-device-format-string(74930)
https://exchange.xforce.ibmcloud.com/vulnerabilities/74930
CopyrightCopyright (C) 2012 E-Soft Inc.

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.