Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-4008

Опубликовано: 14 дек. 2021
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

A flaw was found in the Xorg-x11-server. An out-of-bounds access issue can occur in the SProcRenderCompositeGlyphs function due to improper validation of the request length.

Отчет

Xorg server does not run with root privileges in Red Hat Enterprise Linux 8, therefore this flaw has been rated as having moderate impact for Red Hat Enterprise linux 8.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 9xorg-x11-serverNot affected
Red Hat Enterprise Linux 9xorg-x11-server-XwaylandNot affected
Red Hat Enterprise Linux 7xorg-x11-serverFixedRHSA-2022:000303.01.2022
Red Hat Enterprise Linux 8xorg-x11-serverFixedRHSA-2022:191710.05.2022
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandFixedRHSA-2022:191710.05.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=2026059xorg-x11-server: SProcRenderCompositeGlyphs out-of-bounds access

EPSS

Процентиль: 17%
0.00055
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 3 лет назад

A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 7.8
nvd
больше 3 лет назад

A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 7.8
debian
больше 3 лет назад

A flaw was found in xorg-x11-server in versions before 21.1.2 and befo ...

suse-cvrf
больше 3 лет назад

Security update for xorg-x11-server

suse-cvrf
больше 3 лет назад

Security update for xorg-x11-server

EPSS

Процентиль: 17%
0.00055
Низкий

7.8 High

CVSS3