Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-31083

Опубликовано: 03 апр. 2024
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when AllocateGlyph() is called to store new glyphs sent by the client to the X server, potentially resulting in multiple entries pointing to the same non-refcounted glyphs. Consequently, ProcRenderAddGlyphs() may free a glyph, leading to a use-after-free scenario when the same glyph pointer is subsequently accessed. This flaw allows an authenticated attacker to execute arbitrary code on the system by sending a specially crafted request.

Отчет

Xorg server does not run with root privileges in Red Hat Enterprise Linux 8 and 9, therefore, Red Hat Enterprise Linux 8 and 9 have been rated with a Moderate severity.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6tigervncOut of support scope
Red Hat Enterprise Linux 6xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 7xorg-x11-serverFixedRHSA-2024:178511.04.2024
Red Hat Enterprise Linux 7tigervncFixedRHSA-2024:208029.04.2024
Red Hat Enterprise Linux 8tigervncFixedRHSA-2024:203724.04.2024
Red Hat Enterprise Linux 8xorg-x11-serverFixedRHSA-2024:325822.05.2024
Red Hat Enterprise Linux 8tigervncFixedRHSA-2024:326122.05.2024
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandFixedRHSA-2024:334323.05.2024
Red Hat Enterprise Linux 8.2 Advanced Update SupporttigervncFixedRHSA-2024:204124.04.2024
Red Hat Enterprise Linux 8.2 Telecommunications Update ServicetigervncFixedRHSA-2024:204124.04.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2272000xorg-x11-server: Use-after-free in ProcRenderAddGlyphs

EPSS

Процентиль: 33%
0.00126
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 1 года назад

A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when AllocateGlyph() is called to store new glyphs sent by the client to the X server, potentially resulting in multiple entries pointing to the same non-refcounted glyphs. Consequently, ProcRenderAddGlyphs() may free a glyph, leading to a use-after-free scenario when the same glyph pointer is subsequently accessed. This flaw allows an authenticated attacker to execute arbitrary code on the system by sending a specially crafted request.

CVSS3: 7.8
nvd
около 1 года назад

A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when AllocateGlyph() is called to store new glyphs sent by the client to the X server, potentially resulting in multiple entries pointing to the same non-refcounted glyphs. Consequently, ProcRenderAddGlyphs() may free a glyph, leading to a use-after-free scenario when the same glyph pointer is subsequently accessed. This flaw allows an authenticated attacker to execute arbitrary code on the system by sending a specially crafted request.

CVSS3: 7.8
msrc
10 месяцев назад

Описание отсутствует

CVSS3: 7.8
debian
около 1 года назад

A use-after-free vulnerability was found in the ProcRenderAddGlyphs() ...

suse-cvrf
около 1 года назад

Security update for xorg-x11-server

EPSS

Процентиль: 33%
0.00126
Низкий

7.8 High

CVSS3

Уязвимость CVE-2024-31083