{"id":"USN-4905-2","summary":"xorg-server vulnerability","details":"USN-4905-1 fixed a vulnerability in X.Org. This update provides\nthe corresponding update for Ubuntu 14.04 ESM.\n\nOriginal advisory details:\n\n Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled\n certain lengths of XInput extension ChangeFeedbackControl requests. An\n attacker could use this issue to cause the server to crash, resulting in a\n denial of service, or possibly execute arbitrary code.\n","modified":"2026-06-29T13:48:40.563567064Z","published":"2021-06-30T14:27:28Z","related":["UBUNTU-CVE-2021-3472"],"upstream":["CVE-2021-3472","UBUNTU-CVE-2021-3472"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-4905-2"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-3472"}],"affected":[{"package":{"name":"xorg-server","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/xorg-server?arch=source&distro=trusty%2Fesm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:1.15.1-0ubuntu2.11+esm4"}]}],"versions":["2:1.14.3-3ubuntu2","2:1.14.3-3ubuntu3","2:1.14.3-3ubuntu4","2:1.14.3-5ubuntu1","2:1.14.4-1ubuntu1","2:1.14.4-1ubuntu2","2:1.14.4.901-0ubuntu2","2:1.14.5-1ubuntu2","2:1.14.5-1ubuntu4","2:1.15.0-1ubuntu1","2:1.15.0-1ubuntu2","2:1.15.0-1ubuntu3","2:1.15.0-1ubuntu4","2:1.15.0-1ubuntu6","2:1.15.0-1ubuntu7","2:1.15.1-0ubuntu1","2:1.15.1-0ubuntu2","2:1.15.1-0ubuntu2.1","2:1.15.1-0ubuntu2.4","2:1.15.1-0ubuntu2.5","2:1.15.1-0ubuntu2.6","2:1.15.1-0ubuntu2.7","2:1.15.1-0ubuntu2.9","2:1.15.1-0ubuntu2.10","2:1.15.1-0ubuntu2.11","2:1.15.1-0ubuntu2.11+esm2","2:1.15.1-0ubuntu2.11+esm3"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro","binaries":[{"binary_version":"2:1.15.1-0ubuntu2.11+esm4","binary_name":"xdmx"},{"binary_name":"xdmx-tools","binary_version":"2:1.15.1-0ubuntu2.11+esm4"},{"binary_name":"xnest","binary_version":"2:1.15.1-0ubuntu2.11+esm4"},{"binary_version":"2:1.15.1-0ubuntu2.11+esm4","binary_name":"xorg-server-source"},{"binary_version":"2:1.15.1-0ubuntu2.11+esm4","binary_name":"xserver-common"},{"binary_name":"xserver-xephyr","binary_version":"2:1.15.1-0ubuntu2.11+esm4"},{"binary_name":"xserver-xorg-core","binary_version":"2:1.15.1-0ubuntu2.11+esm4"},{"binary_name":"xserver-xorg-xmir","binary_version":"2:1.15.1-0ubuntu2.11+esm4"},{"binary_name":"xvfb","binary_version":"2:1.15.1-0ubuntu2.11+esm4"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:14.04:LTS","cves":[{"id":"CVE-2021-3472","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4905-2.json"}}],"schema_version":"1.7.5"}