CVE-2017-12185 describes a critical vulnerability in xorg-x11-server versions prior to 1.19.5, affecting Debian and X.Org X servers. The flaw stems from missing length validation in the MIT-SCREEN-SAVER extension, allowing a malicious X client to crash the X server or potentially execute arbitrary code. With a CVSS score of 9.8 (Critical), this vulnerability is network-exploitable with low attack complexity, leading to high impacts on confidentiality, integrity, and availability. While no public exploit intelligence like Metasploit or ExploitDB entries exist, and there's minimal community discussion or media coverage, its high FAUCET Risk Score of 80/100 indicates significant inherent risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
< 1.19.5CPE matchmatch criteria | cpe:2.3:a:x.org:x_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.