Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-0662

Опубликовано: 08 фев. 2023
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2023-0662: tigervnc security update (IMPORTANT)

[1.12.0-9]

  • xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation Resolves: bz#2167057

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

tigervnc

1.12.0-9.el8_7.1

tigervnc-icons

1.12.0-9.el8_7.1

tigervnc-license

1.12.0-9.el8_7.1

tigervnc-selinux

1.12.0-9.el8_7.1

tigervnc-server

1.12.0-9.el8_7.1

tigervnc-server-minimal

1.12.0-9.el8_7.1

tigervnc-server-module

1.12.0-9.el8_7.1

Oracle Linux x86_64

tigervnc

1.12.0-9.el8_7.1

tigervnc-icons

1.12.0-9.el8_7.1

tigervnc-license

1.12.0-9.el8_7.1

tigervnc-selinux

1.12.0-9.el8_7.1

tigervnc-server

1.12.0-9.el8_7.1

tigervnc-server-minimal

1.12.0-9.el8_7.1

tigervnc-server-module

1.12.0-9.el8_7.1

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 2 лет назад

A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote code execution for ssh X forwarding sessions.

CVSS3: 7.8
redhat
больше 2 лет назад

A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote code execution for ssh X forwarding sessions.

CVSS3: 7.8
nvd
около 2 лет назад

A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote code execution for ssh X forwarding sessions.

CVSS3: 7.8
debian
около 2 лет назад

A vulnerability was found in X.Org. This issue occurs due to a danglin ...

suse-cvrf
больше 2 лет назад

Security update for xwayland