CVE-2015-0255
Publication date 11 February 2015
Last updated 24 July 2024
Ubuntu priority
X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (crash) via a crafted string length value in a XkbSetGeometry request.
From the Ubuntu Security Team
USN-2500-1 addressed CVE-2015-0255 for xorg-server. This update provides the corresponding fix for VNC4 on Ubuntu 14.04 ESM.
Status
Package | Ubuntu Release | Status |
---|---|---|
vnc4 | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
18.04 LTS bionic |
Vulnerable
|
|
16.04 LTS xenial |
Fixed 4.1.1+xorg4.3.0-37.3ubuntu2.1+esm1
|
|
14.04 LTS trusty |
Fixed 4.1.1+xorg4.3.0-37ubuntu5.0.2+esm1
|
|
xorg-server | 24.10 oracular |
Fixed 2:1.16.2.901-1ubuntu4
|
24.04 LTS noble |
Fixed 2:1.16.2.901-1ubuntu4
|
|
22.04 LTS jammy |
Fixed 2:1.16.2.901-1ubuntu4
|
|
20.04 LTS focal |
Fixed 2:1.16.2.901-1ubuntu4
|
|
18.04 LTS bionic |
Fixed 2:1.16.2.901-1ubuntu4
|
|
16.04 LTS xenial |
Fixed 2:1.16.2.901-1ubuntu4
|
|
14.04 LTS trusty |
Fixed 2:1.15.1-0ubuntu2.7
|
|
xorg-server-lts-quantal | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
xorg-server-lts-raring | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
xorg-server-lts-saucy | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
xorg-server-lts-trusty | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
xorg-server-lts-utopic | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty |
Fixed 2:1.16.0-1ubuntu1.2~trusty2
|
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu ProPatch details
Package | Patch details |
---|---|
vnc4 | |
xorg-server |
References
Related Ubuntu Security Notices (USN)
- USN-2500-1
- X.Org X server vulnerabilities
- 17 February 2015
- USN-4772-1
- VNC4 vulnerabilities
- 15 March 2021