Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-5380

Опубликовано: 25 окт. 2023
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.

Отчет

The xorg-x11-server-Xwayland package as shipped by Red Hat Enterprise Linux 8 and 9 is not affected by this issue as Xwayland does not support multiple protocol screens and is not affected by this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6tigervncOut of support scope
Red Hat Enterprise Linux 6xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 7xorg-x11-serverAffected
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandNot affected
Red Hat Enterprise Linux 9xorg-x11-server-XwaylandNot affected
Red Hat Enterprise Linux 7tigervncFixedRHSA-2023:742821.11.2023
Red Hat Enterprise Linux 8xorg-x11-serverFixedRHSA-2024:299522.05.2024
Red Hat Enterprise Linux 8tigervncFixedRHSA-2024:306722.05.2024
Red Hat Enterprise Linux 9xorg-x11-serverFixedRHSA-2024:216930.04.2024
Red Hat Enterprise Linux 9tigervncFixedRHSA-2024:229830.04.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2244736xorg-x11-server: Use-after-free bug in DestroyWindow

EPSS

Процентиль: 25%
0.00082
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
больше 1 года назад

A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.

CVSS3: 4.7
nvd
больше 1 года назад

A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.

CVSS3: 4.7
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 4.7
debian
больше 1 года назад

A use-after-free flaw was found in the xorg-x11-server. An X server cr ...

CVSS3: 5.1
github
больше 1 года назад

A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.

EPSS

Процентиль: 25%
0.00082
Низкий

4.7 Medium

CVSS3