Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-6377

Опубликовано: 13 дек. 2023
Источник: debian
EPSS Низкий

Описание

A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xorg-serverfixed2:21.1.10-1package
xwaylandfixed2:23.2.3-1package
xwaylandignoredbookwormpackage

Примечания

  • https://lists.x.org/archives/xorg-announce/2023-December/003435.html

  • Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/0c1a93d319558fe3ab2d94f51d174b4f93810afd

EPSS

Процентиль: 61%
0.00411
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 2 года назад

A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.

CVSS3: 7.8
redhat
почти 2 года назад

A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.

CVSS3: 7.8
nvd
почти 2 года назад

A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.

CVSS3: 7.8
msrc
почти 2 года назад

Xorg-x11-server: out-of-bounds memory reads/writes in xkb button actions

suse-cvrf
почти 2 года назад

Security update for xorg-x11-server

EPSS

Процентиль: 61%
0.00411
Низкий