CVE-2015-0255
Published: 11 February 2015
X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (crash) via a crafted string length value in a XkbSetGeometry request.
From the Ubuntu security team
USN-2500-1 addressed CVE-2015-0255 for xorg-server. This update provides the corresponding fix for VNC4 on Ubuntu 14.04 ESM.
Priority
Status
Package | Release | Status |
---|---|---|
vnc4 Launchpad, Ubuntu, Debian |
artful |
Ignored
(reached end-of-life)
|
bionic |
Needed
|
|
cosmic |
Ignored
(reached end-of-life)
|
|
disco |
Not vulnerable
(transitional package)
|
|
eoan |
Not vulnerable
(transitional package)
|
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
lucid |
Ignored
(reached end-of-life)
|
|
precise |
Does not exist
(precise was needed)
|
|
trusty |
Needed
|
|
upstream |
Needed
|
|
utopic |
Ignored
(reached end-of-life)
|
|
vivid |
Ignored
(reached end-of-life)
|
|
wily |
Ignored
(reached end-of-life)
|
|
xenial |
Ignored
(end of standard support, was needed)
|
|
yakkety |
Ignored
(reached end-of-life)
|
|
zesty |
Ignored
(reached end-of-life)
|
|
xorg-server Launchpad, Ubuntu, Debian |
artful |
Released
(2:1.16.2.901-1ubuntu4)
|
bionic |
Released
(2:1.16.2.901-1ubuntu4)
|
|
cosmic |
Released
(2:1.16.2.901-1ubuntu4)
|
|
disco |
Released
(2:1.16.2.901-1ubuntu4)
|
|
eoan |
Released
(2:1.16.2.901-1ubuntu4)
|
|
focal |
Released
(2:1.16.2.901-1ubuntu4)
|
|
groovy |
Released
(2:1.16.2.901-1ubuntu4)
|
|
hirsute |
Released
(2:1.16.2.901-1ubuntu4)
|
|
impish |
Released
(2:1.16.2.901-1ubuntu4)
|
|
jammy |
Released
(2:1.16.2.901-1ubuntu4)
|
|
lucid |
Ignored
(reached end-of-life)
|
|
precise |
Does not exist
(precise was released [2:1.11.4-0ubuntu10.17])
|
|
trusty |
Released
(2:1.15.1-0ubuntu2.7)
|
|
upstream |
Needed
|
|
utopic |
Released
(2:1.16.0-1ubuntu1.3)
|
|
vivid |
Released
(2:1.16.2.901-1ubuntu4)
|
|
wily |
Released
(2:1.16.2.901-1ubuntu4)
|
|
xenial |
Released
(2:1.16.2.901-1ubuntu4)
|
|
yakkety |
Released
(2:1.16.2.901-1ubuntu4)
|
|
zesty |
Released
(2:1.16.2.901-1ubuntu4)
|
|
xorg-server-lts-quantal Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
bionic |
Does not exist
|
|
cosmic |
Does not exist
|
|
disco |
Does not exist
|
|
eoan |
Does not exist
|
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
lucid |
Does not exist
|
|
precise |
Does not exist
(precise was ignored [reached end-of-life])
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
utopic |
Does not exist
|
|
vivid |
Does not exist
|
|
wily |
Does not exist
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
xorg-server-lts-raring Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
bionic |
Does not exist
|
|
cosmic |
Does not exist
|
|
disco |
Does not exist
|
|
eoan |
Does not exist
|
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
lucid |
Does not exist
|
|
precise |
Does not exist
(precise was ignored [reached end-of-life])
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
utopic |
Does not exist
|
|
vivid |
Does not exist
|
|
wily |
Does not exist
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
xorg-server-lts-saucy Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
bionic |
Does not exist
|
|
cosmic |
Does not exist
|
|
disco |
Does not exist
|
|
eoan |
Does not exist
|
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
lucid |
Does not exist
|
|
precise |
Does not exist
(precise was ignored [reached end-of-life])
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
utopic |
Does not exist
|
|
vivid |
Does not exist
|
|
wily |
Does not exist
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
xorg-server-lts-trusty Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
bionic |
Does not exist
|
|
cosmic |
Does not exist
|
|
disco |
Does not exist
|
|
eoan |
Does not exist
|
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
lucid |
Does not exist
|
|
precise |
Does not exist
(precise was released [2:1.15.1-0ubuntu2~precise5])
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
utopic |
Does not exist
|
|
vivid |
Does not exist
|
|
wily |
Does not exist
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
xorg-server-lts-utopic Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
bionic |
Does not exist
|
|
cosmic |
Does not exist
|
|
disco |
Does not exist
|
|
eoan |
Does not exist
|
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
lucid |
Does not exist
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
(trusty was released [2:1.16.0-1ubuntu1.2~trusty2])
|
|
upstream |
Needs triage
|
|
utopic |
Does not exist
|
|
vivid |
Does not exist
|
|
wily |
Does not exist
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|