Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-1393

Опубликовано: 30 мар. 2023
Источник: debian
EPSS Низкий

Описание

A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xorg-serverfixed2:21.1.7-2package
xwaylandfixed2:22.1.9-1package

Примечания

  • https://www.openwall.com/lists/oss-security/2023/03/29/1

  • https://gitlab.freedesktop.org/xorg/xserver/-/commit/26ef545b3502f61ca722a7a3373507e88ef64110

EPSS

Процентиль: 20%
0.00062
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 2 лет назад

A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.

CVSS3: 7.8
redhat
больше 2 лет назад

A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.

CVSS3: 7.8
nvd
больше 2 лет назад

A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.

CVSS3: 7.8
msrc
11 месяцев назад

Описание отсутствует

suse-cvrf
больше 2 лет назад

Security update for xwayland

EPSS

Процентиль: 20%
0.00062
Низкий