Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server.
References
| Link | Resource |
|---|---|
| http://www.debian.org/security/2017/dsa-3905 | |
| http://www.securityfocus.com/bid/99543 | Third Party Advisory VDB Entry |
| https://bugzilla.suse.com/show_bug.cgi?id=1035283 | Issue Tracking Third Party Advisory |
| https://cgit.freedesktop.org/xorg/xserver/commit/?id=05442de962d3dc624f79fc1a00eca3ffc5489ced | Patch Third Party Advisory |
| http://www.debian.org/security/2017/dsa-3905 | |
| http://www.securityfocus.com/bid/99543 | Third Party Advisory VDB Entry |
| https://bugzilla.suse.com/show_bug.cgi?id=1035283 | Issue Tracking Third Party Advisory |
| https://cgit.freedesktop.org/xorg/xserver/commit/?id=05442de962d3dc624f79fc1a00eca3ffc5489ced | Patch Third Party Advisory |
Configurations
History
29 Aug 2025, 13:42
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:x.org:x_server:*:*:*:*:*:*:*:* | |
| First Time |
X.org x Server
|
Information
Published : 2017-07-06 11:29
Updated : 2025-08-29 13:42
NVD link : CVE-2017-10972
Mitre link : CVE-2017-10972
CVE.ORG link : CVE-2017-10972
JSON object : View
Products Affected
x.org
- x_server
CWE
CWE-665
Improper Initialization
