Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-0494
HistoryMar 27, 2023 - 9:15 p.m.

Design/Logic Flaw

2023-03-2721:15:00
PRIOn knowledge base
www.prio-n.com
5
x.org
vulnerability
local privilege elevation
remote code execution
security issue
memory exploitation

7.8 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

51.9%

A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote code execution for ssh X forwarding sessions.