CVE-2023-0494
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote code execution for ssh X forwarding sessions.
Affected (35)
Products: X.org: X Server · Fedoraproject: Fedora · Redhat: Enterprise Linux, Enterprise Linux Aus, Enterprise Linux Desktop, Enterprise Linux Eus, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Ibm Z Systems Eus, Enterprise Linux For Power Big Endian, Enterprise Linux For Power Little Endian, Enterprise Linux For Power Little Endian Eus, Enterprise Linux For Scientific Computing, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions, Enterprise Linux Server Tus, Enterprise Linux Server Update Services For Sap Solutions, Enterprise Linux Server Workstation
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 36 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 | |
| Version 8.4 | |
| Version 7.0 | |
| Version 8.4 | |
| Version 7.0 | |
| Version 8.4 | |
| Version 7.0 | |
| Version 7.0 | |
| Version 8.4 | |
| Version 7.0 | |
| Version 7.0 | |
| Version 8.2 | |
| Version 8.1 | |
| Version 8.2 | |
| Version 8.2 | |
| Version 7.0 |
References (8)
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Patch
Source: secalert@redhat.com
Mailing ListVendor Advisory
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.