Lucene search

K
freebsdFreeBSD6CC63BF5-A727-4155-8EC4-68B626475E68
HistoryFeb 07, 2023 - 12:00 a.m.

xorg-server -- Security issue in the X server

2023-02-0700:00:00
vuxml.freebsd.org
9
x.org server
security issue
dangling pointer

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

51.9%

The X.org project reports:

CVE-2023-0494/ZDI-CAN-19596: X.Org Server DeepCopyPointerClasses
use-after-free

    A dangling pointer in DeepCopyPointerClasses can be exploited by
    ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read/write into
    freed memory.

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

51.9%