Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2320

Опубликовано: 12 июл. 2022
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.

Отчет

Xorg server does not run with root privileges in Red Hat Enterprise Linux 8, therefore this flaw has been rated as having Moderate impact.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 7xorg-x11-serverFixedRHSA-2022:590504.08.2022
Red Hat Enterprise Linux 8xorg-x11-serverFixedRHSA-2022:758308.11.2022
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandFixedRHSA-2022:758308.11.2022
Red Hat Enterprise Linux 9xorg-x11-serverFixedRHSA-2022:822115.11.2022
Red Hat Enterprise Linux 9xorg-x11-server-XwaylandFixedRHSA-2022:822215.11.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2106683xorg-x11-server: out-of-bounds access in ProcXkbSetDeviceInfo request handler of the Xkb extension

EPSS

Процентиль: 10%
0.00035
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 3 лет назад

A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.

CVSS3: 7.8
nvd
около 3 лет назад

A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.

CVSS3: 7.8
debian
около 3 лет назад

A flaw was found in the Xorg-x11-server. The specific flaw exists with ...

CVSS3: 7.8
github
около 3 лет назад

A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.

CVSS3: 7.8
fstec
почти 4 года назад

Уязвимость обработчика вызовов ProcXkbSetDeviceInfo сервера X.Org Server, позволяющая нарушителю выполнить произвольный код или повысить свои привилегии

EPSS

Процентиль: 10%
0.00035
Низкий

7.8 High

CVSS3