Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-5574

Опубликовано: 25 окт. 2023
Источник: redhat
CVSS3: 7

Описание

A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service.

Отчет

Xvfb does not run with root privileges in Red Hat Enterprise Linux 7, 8, and 9, therefore, Red Hat Enterprise Linux 7, 8, and 9 have been rated with a moderate severity. The xorg-x11-server-Xwayland package as shipped by Red Hat Enterprise Linux 8 and 9 is not affected by this issue as Xwayland does not support multiple protocol screens and is not affected by this vulnerability.

Меры по смягчению последствий

Starting Xvfb with the -noreset command line option limits the use-after-free from being triggered only at the Xvfb server shutdown. Also, do not start Xvfb as root.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6tigervncOut of support scope
Red Hat Enterprise Linux 6xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 7tigervncNot affected
Red Hat Enterprise Linux 7xorg-x11-serverAffected
Red Hat Enterprise Linux 8tigervncNot affected
Red Hat Enterprise Linux 8xorg-x11-serverWill not fix
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandNot affected
Red Hat Enterprise Linux 9xorg-x11-serverWill not fix
Red Hat Enterprise Linux 9xorg-x11-server-XwaylandNot affected
Red Hat Enterprise Linux 9tigervncFixedRHSA-2024:229830.04.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2244735xorg-x11-server: Use-after-free bug in DamageDestroy

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
больше 1 года назад

A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service.

CVSS3: 7
nvd
больше 1 года назад

A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service.

CVSS3: 7
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7
debian
больше 1 года назад

A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue oc ...

CVSS3: 7
github
больше 1 года назад

A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service.

7 High

CVSS3