Xorg-x11-server: out-of-bounds write in xichangedeviceproperty/rrchangeoutputproperty
CVE-2023-5367
7.8HIGH
Key Information:
- Vendor
- Red Hat
- Status
- Vendor
- CVE Published:
- 25 October 2023
Summary
A vulnerability exists in the Xorg-X11 Server that stems from an incorrect buffer offset calculation within the XIChangeDeviceProperty and RRChangeOutputProperty functions. This flaw can lead to out-of-bounds writes, which may enable attackers to escalate privileges or induce denial of service conditions. Addressing this issue is critical for maintaining the integrity and security of systems running affected versions of the Xorg-X11 Server.
Affected Version(s)
Red Hat Enterprise Linux 7 0:1.20.4-24.el7_9
Red Hat Enterprise Linux 7 0:1.8.0-26.el7_9
Red Hat Enterprise Linux 8 0:1.13.1-2.el8_9.1
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database