oss-sec mailing list archives

Re: Question about CVE for X!! DoS


From: Julien Cristau <jcristau () debian org>
Date: Fri, 5 Jul 2013 23:06:39 +0200

On Fri, Jul  5, 2013 at 14:50:17 -0600, Kurt Seifried wrote:

http://lists.opensuse.org/opensuse-updates/2013-07/msg00023.html
https://bugzilla.novell.com/show_bug.cgi?id=815583

Lists no CVE? I assume it needs one, or did upstream handle this?

If you can connect to an X server, DoSing it is trivial (think
XGrabServer).  This has never been considered a security issue AFAIK.

Cheers,
Julien


Current thread: