Buffer Over-read in Mesa Graphics Software by FreeDesktop
CVE-2023-45919

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
27 March 2024

What is CVE-2023-45919?

Mesa version 23.0.4 is affected by a buffer over-read vulnerability in the glXQueryServerString() function. While the issue has been noted, its practical implications are subject to debate, as there appear to be limited scenarios where uninterrupted operation is required when interacting with an attacker-controlled server. This situation raises questions about the exploit efficacy and relevance of the vulnerability in real-world conditions.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-45919 : Buffer Over-read in Mesa Graphics Software by FreeDesktop