ZeroHour

CVE-2018-15859

CVSS 3.0
5.5 medium
EPSS
<1%p44
Published
()
Modified
Description

Unchecked NULL pointer usage when parsing invalid atoms in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because lookup failures are mishandled.

Vendors
xkbcommoncanonical
Products
libxkbcommon, xkbcommon, ubuntu linux
Weakness
CWE-476
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.