Memory Management Vulnerability in X.Org Affecting ScreenSaverSetAttributes
CVE-2022-46343

8.8HIGH

Key Information:

Vendor

X.org

Vendor
CVE Published:
14 December 2022

What is CVE-2022-46343?

A vulnerability exists within the X.Org Server related to improper handling of the ScreenSaverSetAttributes request. This flaw allows for memory to be written after it has been freed, posing significant risks on systems running the X server with elevated privileges. This vulnerability can enable local privilege escalation and create potential opportunities for remote code execution through SSH X forwarding sessions, impacting the overall security posture of affected systems.

Affected Version(s)

xorg-x11-server xorg-x11-server-1.20.4

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.