Xorg-x11-server: out-of-bounds write in xichangedeviceproperty/rrchangeoutputproperty
CVE-2023-5367

7.8HIGH

Summary

A vulnerability exists in the Xorg-X11 Server that stems from an incorrect buffer offset calculation within the XIChangeDeviceProperty and RRChangeOutputProperty functions. This flaw can lead to out-of-bounds writes, which may enable attackers to escalate privileges or induce denial of service conditions. Addressing this issue is critical for maintaining the integrity and security of systems running affected versions of the Xorg-X11 Server.

Affected Version(s)

Red Hat Enterprise Linux 7 0:1.20.4-24.el7_9

Red Hat Enterprise Linux 7 0:1.8.0-26.el7_9

Red Hat Enterprise Linux 8 0:1.13.1-2.el8_9.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.