CVE-2015-0255: Opensuse

Medium severity, CVSS 6.4. EPSS: 4.5% chance of exploitation in the next 30 days.

X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (crash) via a crafted string length value in a XkbSetGeometry request.

Affected products

  • Opensuse Opensuse: version 13.1 only; version 13.2 only
  • X.org X Server: up to and including 1.16.3; version 1.17.0 only

Published 2015-02-13. Last modified 2026-06-17.