Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2320

Опубликовано: 12 июл. 2022
Источник: redhat
CVSS3: 7.8

Описание

A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.

Отчет

Xorg server does not run with root privileges in Red Hat Enterprise Linux 8, therefore this flaw has been rated as having Moderate impact.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 7xorg-x11-serverFixedRHSA-2022:590504.08.2022
Red Hat Enterprise Linux 8xorg-x11-serverFixedRHSA-2022:758308.11.2022
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandFixedRHSA-2022:758308.11.2022
Red Hat Enterprise Linux 9xorg-x11-serverFixedRHSA-2022:822115.11.2022
Red Hat Enterprise Linux 9xorg-x11-server-XwaylandFixedRHSA-2022:822215.11.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2106683xorg-x11-server: out-of-bounds access in ProcXkbSetDeviceInfo request handler of the Xkb extension

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 3 года назад

A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.

CVSS3: 7.8
nvd
почти 3 года назад

A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.

CVSS3: 7.8
debian
почти 3 года назад

A flaw was found in the Xorg-x11-server. The specific flaw exists with ...

CVSS3: 7.8
github
почти 3 года назад

A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.

CVSS3: 7.8
fstec
больше 3 лет назад

Уязвимость обработчика вызовов ProcXkbSetDeviceInfo сервера X.Org Server, позволяющая нарушителю выполнить произвольный код или повысить свои привилегии

7.8 High

CVSS3