Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3550

Опубликовано: 17 окт. 2022
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051.

A flaw was found in the xorg-x11-server package. A buffer overflow can occur in the _GetCountedString function in xkb/xkb.c due to improper input validation, allowing for possible escalation of privileges, execution of arbitrary code, or a denial of service.

Отчет

Xorg server does not run with root privileges in Red Hat Enterprise Linux 8 and 9, therefore Red Hat Enterprise Linux 8 and 9 have been rated with a moderate severity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 7xorg-x11-serverFixedRHSA-2022:849116.11.2022
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandFixedRHSA-2023:280516.05.2023
Red Hat Enterprise Linux 8xorg-x11-serverFixedRHSA-2023:280616.05.2023
Red Hat Enterprise Linux 9xorg-x11-serverFixedRHSA-2023:224809.05.2023
Red Hat Enterprise Linux 9xorg-x11-server-XwaylandFixedRHSA-2023:224909.05.2023

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-119
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2140698xorg-x11-server: buffer overflow in _GetCountedString() in xkb/xkb.c

EPSS

Процентиль: 47%
0.00241
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 2 лет назад

A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051.

CVSS3: 5.5
nvd
больше 2 лет назад

A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051.

CVSS3: 5.5
debian
больше 2 лет назад

A vulnerability classified as critical was found in X.org Server. Affe ...

CVSS3: 9.8
github
больше 2 лет назад

A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051.

CVSS3: 8.8
fstec
почти 3 года назад

Уязвимость функции GetCountedString компонента xkb/xkb.c реализации сервера X Window System X.Org Server, реализации протокола Wayland для X.Org XWayland, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 47%
0.00241
Низкий

8.8 High

CVSS3