Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-49179

Опубликовано: 17 июн. 2025
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer overflow when computing request length, which allows a client to bypass length checks.

Отчет

This vulnerability is rated as an important severity because the flaw exists in the X Record extension of the X.Org X server within the RecordSanityCheckRegisterClients function, which fails to validate integer overflows when calculating the length of client registration requests. As a result, the server may read or write beyond intended memory bounds, leading primarily to denial of service by crashing the process, possibility of leaking memory contents or corrupting data.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xorg-x11-serverWill not fix
Red Hat Enterprise Linux 10xorg-x11-server-XwaylandFixedRHSA-2025:930423.06.2025
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONtigervncFixedRHSA-2025:1037707.07.2025
Red Hat Enterprise Linux 7.7 Advanced Update SupporttigervncFixedRHSA-2025:1037607.07.2025
Red Hat Enterprise Linux 7 Extended Lifecycle Supportxorg-x11-serverFixedRHSA-2025:1036007.07.2025
Red Hat Enterprise Linux 7 Extended Lifecycle SupporttigervncFixedRHSA-2025:1037507.07.2025
Red Hat Enterprise Linux 8xorg-x11-serverFixedRHSA-2025:930523.06.2025
Red Hat Enterprise Linux 8xorg-x11-server-XwaylandFixedRHSA-2025:930523.06.2025
Red Hat Enterprise Linux 8tigervncFixedRHSA-2025:939223.06.2025
Red Hat Enterprise Linux 8.2 Advanced Update SupporttigervncFixedRHSA-2025:1037807.07.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2369978xorg-x11-server-Xwayland: xorg-x11-server: tigervnc: Integer overflow in X Record extension

EPSS

Процентиль: 3%
0.00019
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
около 2 месяцев назад

A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer overflow when computing request length, which allows a client to bypass length checks.

CVSS3: 7.3
nvd
около 2 месяцев назад

A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer overflow when computing request length, which allows a client to bypass length checks.

CVSS3: 7.3
debian
около 2 месяцев назад

A flaw was found in the X Record extension. The RecordSanityCheckRegis ...

CVSS3: 6.6
github
около 2 месяцев назад

A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer overflow when computing request length, which allows a client to bypass length checks.

CVSS3: 6.6
fstec
4 месяца назад

Уязвимость функции RecordSanityCheckRegisterClients() сервера X Window System Xorg-server, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 3%
0.00019
Низкий

7.3 High

CVSS3