CVE-2019-17624

HIGH

X.org X Server < 1.20.4 - Out-of-Bounds Write

Title source: rule

Description

"" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sending ct.c_char 1000 times, an attacker can cause a denial of service (application crash) or possibly have unspecified other impact. Note: It is disputed if the X.Org X Server is involved or if there is a stack overflow.

Exploits (1)

exploitdb WORKING POC
by s4vitar · pythonlocallinux
https://www.exploit-db.com/exploits/47507

Scores

CVSS v3 7.8
EPSS 0.1623
EPSS Percentile 94.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (1)
x.org/x_server < 1.20.4
Published Oct 16, 2019
Tracked Since Feb 18, 2026