Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-5574

Опубликовано: 25 окт. 2023
Источник: debian
EPSS Низкий

Описание

A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xorg-serverunfixedpackage
xorg-serverpostponedtrixiepackage
xorg-serverpostponedbookwormpackage
xorg-serverno-dsabullseyepackage
xorg-serverno-dsabusterpackage

Примечания

  • https://lists.x.org/archives/xorg-announce/2023-October/003430.html

  • https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/1189

EPSS

Процентиль: 9%
0.00035
Низкий

Связанные уязвимости

CVSS3: 7
ubuntu
больше 1 года назад

A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service.

CVSS3: 7
redhat
больше 1 года назад

A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service.

CVSS3: 7
nvd
больше 1 года назад

A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service.

CVSS3: 7
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7
github
больше 1 года назад

A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service.

EPSS

Процентиль: 9%
0.00035
Низкий