libX11 Insufficient Length Check / Injection

A missing length check in libX11 allows data from LookupColor requests to mess up the client-server communication protocol and inject malicious X server requests.

Leave a Reply