User enumeration In xorg-server
Description
It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is seen, this causes a time difference between a valid and invalid byte, which could allow an efficient brute force attack.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 14 | 2:1.19.2-1 | ||
debian 12 | 2:1.19.2-1 | ||
debian 13 | 2:1.19.2-1 | ||
rpm rhel7 | - | - | |
debian 11 | 2:1.19.2-1 | ||
rpm rhel5 | - | - | |
rpm rhel6 | - | - |
Aliases
1. 2. 3. 4. 5.