Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38589
HistoryDec 24, 2022 - 7:33 a.m.

Information Disclosure

2022-12-2407:33:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
xorg-server
information disclosure
vulnerability
length validation
out-of-bound memory reads
sensitive information

0.033 Low

EPSS

Percentile

91.4%

xorg-server is vulnerable to Information Disclosure. The vulnerability exists because the library does not properly validate the length of XIChangeProperty request, resulting in out-of-bound memory reads and sensitive information disclosure

References