Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-6377

Опубликовано: 13 дек. 2023
Источник: debian
EPSS Низкий

Описание

A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xorg-serverfixed2:21.1.10-1package
xwaylandfixed2:23.2.3-1package
xwaylandignoredbookwormpackage

Примечания

  • https://lists.x.org/archives/xorg-announce/2023-December/003435.html

  • Fixed by: https://gitlab.freedesktop.org/xorg/xserver/-/commit/0c1a93d319558fe3ab2d94f51d174b4f93810afd

EPSS

Процентиль: 61%
0.00411
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 1 года назад

A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.

CVSS3: 7.8
redhat
больше 1 года назад

A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.

CVSS3: 7.8
nvd
больше 1 года назад

A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.

suse-cvrf
больше 1 года назад

Security update for xorg-x11-server

suse-cvrf
больше 1 года назад

Security update for xorg-x11-server

EPSS

Процентиль: 61%
0.00411
Низкий