Untriaged
Permalink
CVE-2023-5367
7.8 HIGH
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
Xorg-x11-server: out-of-bounds write in xichangedeviceproperty/rrchangeoutputproperty
A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation of privileges or denial of service.
References
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202401-30 x_transferred
-
https://security.netapp.com/advisory/ntap-20231130-0004/ x_transferred
-
https://www.debian.org/security/2023/dsa-5534 x_transferred
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202401-30 x_transferred
-
https://security.netapp.com/advisory/ntap-20231130-0004/ x_transferred
-
https://www.debian.org/security/2023/dsa-5534 x_transferred
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202401-30 x_transferred
-
https://security.netapp.com/advisory/ntap-20231130-0004/ x_transferred
-
https://www.debian.org/security/2023/dsa-5534 x_transferred
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202401-30 x_transferred
-
https://security.netapp.com/advisory/ntap-20231130-0004/ x_transferred
-
https://www.debian.org/security/2023/dsa-5534 x_transferred
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202401-30 x_transferred
-
https://security.netapp.com/advisory/ntap-20231130-0004/ x_transferred
-
https://www.debian.org/security/2023/dsa-5534 x_transferred
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202401-30 x_transferred
-
https://security.netapp.com/advisory/ntap-20231130-0004/ x_transferred
-
https://www.debian.org/security/2023/dsa-5534 x_transferred
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202401-30 x_transferred
-
https://security.netapp.com/advisory/ntap-20231130-0004/ x_transferred
-
https://www.debian.org/security/2023/dsa-5534 x_transferred
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202401-30 x_transferred
-
https://security.netapp.com/advisory/ntap-20231130-0004/ x_transferred
-
https://www.debian.org/security/2023/dsa-5534 x_transferred
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202401-30 x_transferred
-
https://security.netapp.com/advisory/ntap-20231130-0004/ x_transferred
-
https://www.debian.org/security/2023/dsa-5534 x_transferred
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202401-30 x_transferred
-
https://security.netapp.com/advisory/ntap-20231130-0004/ x_transferred
-
https://www.debian.org/security/2023/dsa-5534 x_transferred
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
https://security.gentoo.org/glsa/202401-30 x_transferred
-
https://security.netapp.com/advisory/ntap-20231130-0004/ x_transferred
-
https://www.debian.org/security/2023/dsa-5534 x_transferred
Affected products
tigervnc
- *
xwayland
- ==23.2.2
xorg-server
- ==21.1.9
xorg-x11-server
- *
xorg-x11-server-Xwayland
- *