Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-31083

Опубликовано: 03 апр. 2024
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when AllocateGlyph() is called to store new glyphs sent by the client to the X server, potentially resulting in multiple entries pointing to the same non-refcounted glyphs. Consequently, ProcRenderAddGlyphs() may free a glyph, leading to a use-after-free scenario when the same glyph pointer is subsequently accessed. This flaw allows an authenticated attacker to execute arbitrary code on the system by sending a specially crafted request.

Отчет

Xorg server does not run with root privileges in Red Hat Enterprise Linux 8 and 9, therefore, Red Hat Enterprise Linux 8 and 9 have been rated with a Moderate severity.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tigervncNot affected
Red Hat Enterprise Linux 10xorg-x11-serverNot affected
Red Hat Enterprise Linux 10xorg-x11-server-XwaylandNot affected
Red Hat Enterprise Linux 6xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONtigervncFixedRHSA-2025:1275104.08.2025
Red Hat Enterprise Linux 7xorg-x11-serverFixedRHSA-2024:178511.04.2024
Red Hat Enterprise Linux 7tigervncFixedRHSA-2024:208029.04.2024
Red Hat Enterprise Linux 8tigervncFixedRHSA-2024:203724.04.2024
Red Hat Enterprise Linux 8xorg-x11-serverFixedRHSA-2024:325822.05.2024
Red Hat Enterprise Linux 8tigervncFixedRHSA-2024:326122.05.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2272000xorg-x11-server: Use-after-free in ProcRenderAddGlyphs

EPSS

Процентиль: 33%
0.0013
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 1 года назад

A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when AllocateGlyph() is called to store new glyphs sent by the client to the X server, potentially resulting in multiple entries pointing to the same non-refcounted glyphs. Consequently, ProcRenderAddGlyphs() may free a glyph, leading to a use-after-free scenario when the same glyph pointer is subsequently accessed. This flaw allows an authenticated attacker to execute arbitrary code on the system by sending a specially crafted request.

CVSS3: 7.8
nvd
больше 1 года назад

A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when AllocateGlyph() is called to store new glyphs sent by the client to the X server, potentially resulting in multiple entries pointing to the same non-refcounted glyphs. Consequently, ProcRenderAddGlyphs() may free a glyph, leading to a use-after-free scenario when the same glyph pointer is subsequently accessed. This flaw allows an authenticated attacker to execute arbitrary code on the system by sending a specially crafted request.

CVSS3: 7.8
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 7.8
debian
больше 1 года назад

A use-after-free vulnerability was found in the ProcRenderAddGlyphs() ...

suse-cvrf
больше 1 года назад

Security update for xorg-x11-server

EPSS

Процентиль: 33%
0.0013
Низкий

7.8 High

CVSS3

Уязвимость CVE-2024-31083