Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h54w-qqq6-jp69

Опубликовано: 17 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051.

A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051.

EPSS

Процентиль: 47%
0.00241
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-119
CWE-120

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 2 лет назад

A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051.

CVSS3: 8.8
redhat
больше 2 лет назад

A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051.

CVSS3: 5.5
nvd
больше 2 лет назад

A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051.

CVSS3: 5.5
debian
больше 2 лет назад

A vulnerability classified as critical was found in X.org Server. Affe ...

CVSS3: 8.8
fstec
почти 3 года назад

Уязвимость функции GetCountedString компонента xkb/xkb.c реализации сервера X Window System X.Org Server, реализации протокола Wayland для X.Org XWayland, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 47%
0.00241
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-119
CWE-120