← Back

CVE-2012-1699

nvd nist
Published: Dec 21, 2012Modified: Apr 29, 2026

JSON object

Loading...
3.6
Vector
AV:L/AC:L/Au:N/C:P/I:N/A:P
Exploitability: 3.9 / Impact: 4.9
Source: NVD

Description

The ProcSetEventMask function in difs/events.c in the xfs font server for X.Org X11R6 through X11R6.6 and XFree86 before 3.3.3 calls the SendErrToClient function with a mask value instead of a pointer, which allows local users to cause a denial of service (memory corruption and crash) or obtain potentially sensitive information from memory via a SetEventMask request that triggers an invalid pointer dereference.

Affected (7)

Products: X: X.org X11 · Xfree86: Xfree86
1 product
X.org X11
1 product
Xfree86
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
X
Version 6.0
Version 6.1
Version 6.3
Version 6.4
Version 6.5.1
Version 6.6
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.3.2

Timeline

No history available yet.