CVE-2015-3164: Opensuse
Low severity, CVSS 3.6. EPSS: 0.4% chance of exploitation in the next 30 days.
The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.
Affected products
- Opensuse Opensuse: version 13.2 only
- X.org X Server: version 1.16.0 only; version 1.16.1 only; version 1.16.1.901 only; version 1.16.2 only; version 1.16.2.901 only; version 1.16.3 only; …
- X.org Xorg-Server: version 1.16.4 only; version 1.16.99.901 only; version 1.16.99.902 only; version 1.17.1 only
Published 2015-07-01. Last modified 2026-06-17.