Untriaged
Permalink
CVE-2023-43787
7.8 HIGH
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): REQUIRED
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
Libx11: integer overflow in xcreateimage() leading to a heap overflow
A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges.
References
-
-
-
-
-
http://www.openwall.com/lists/oss-security/2024/01/24/9 x_transferred
-
https://security.netapp.com/advisory/ntap-20231103-0006/ x_transferred
Affected products
libX11
- *
- <1.8.7
- ==1.8.7
Matching in nixpkgs
pkgs.xorg.libX11
None
pkgs.tests.pkg-config.defaultPkgConfigPackages.x11
Test whether libX11-1.8.12 exposes pkg-config modules x11