Lucene search

K
mageiaGentoo FoundationMGASA-2023-0131
HistoryApr 11, 2023 - 10:02 p.m.

Updated tigervnc/x11-server packages fix security vulnerability

2023-04-1122:02:20
Gentoo Foundation
advisories.mageia.org
15
tigervnc x11-server security vulnerability fix use-after-free unix privilege escalation.

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

15.9%

A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later. (CVE-2023-1393)

OSVersionArchitecturePackageVersionFilename
Mageia8noarchtigervnc< 1.11.0-4.3tigervnc-1.11.0-4.3.mga8
Mageia8noarchx11-server< 1.20.14-4.3x11-server-1.20.14-4.3.mga8

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

15.9%