Lucene search

K
rosalinuxROSA LABROSA-SA-2023-2125
HistoryFeb 28, 2023 - 10:13 a.m.

Advisory ROSA-SA-2023-2125

2023-02-2810:13:13
ROSA LAB
abf.rosalinux.ru
11
vulnerability
xorg-x11-server
privilege escalation
remote code execution
fixed
rosa-sa-2023-2125
cve-2023-0494

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

51.9%

Software: xorg-x11-server 1.20.4
OS: rosa-server79

package_evr_string: xorg-x11-server-common-1.20.4-16.

CVE-ID: CVE-2023-0494
BDU-ID: None
CVE-Crit: HIGH
CVE-DESC: A vulnerability has been discovered in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be used by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write to freed memory. This can lead to local privilege escalation on systems where the X server performs privileged and remote code execution for ssh X forwarding sessions.
CVE-STATUS: Fixed
CVE-REV: To close, run the yum update command

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

51.9%