AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-2624

MEDIUM · CVSS 5.9 EPSS 0.67%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-07-27 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2017-2624
Severity
MEDIUM
CVSS
5.9
EPSS
0.67%

Original NVD Description

It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is seen, this causes a time difference between a valid and invalid byte, which could allow an efficient brute force attack.