CVE-2022-3550
published 2022-10-17CVE-2022-3550: A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The…
PriorityP352high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.42%
69.9th percentile
A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | xorg-server | < xorg-server 2:21.1.4-3 (bookworm) | xorg-server 2:21.1.4-3 (bookworm) |
| debian | xwayland | < xorg-server 2:21.1.4-3 (bookworm) | xorg-server 2:21.1.4-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| x.org | server | — | — |
| x.org | x_server | < 21.1.6 | 21.1.6 |
| x.org | xorg-server | >= 0 < 2:1.20.11-1+deb11u3 | 2:1.20.11-1+deb11u3 |
| x.org | xorg-server | >= 0 < 2:21.1.4-3 | 2:21.1.4-3 |
| x.org | xorg-server | >= 0 < 2:21.1.4-3 | 2:21.1.4-3 |
| x.org | xorg-server | >= 0 < 2:21.1.4-3 | 2:21.1.4-3 |
| x.org | xwayland | >= 0 < 2:22.1.5-1 | 2:22.1.5-1 |
| x.org | xwayland | >= 0 < 2:22.1.5-1 | 2:22.1.5-1 |
| x.org | xwayland | >= 0 < 2:22.1.5-1 | 2:22.1.5-1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.Org X Server vulnerabilities
vendor_ubuntu·2022-11-23
CVE-2022-3550 X.Org X Server vulnerabilities
Title: X.Org X Server vulnerabilities
Summary: Several security issues were fixed in X.Org X Server.
It was discovered that X.Org X Server incorrectly handled certain inputs.
An attacker could use these issues to cause the server to crash, resulting
in a denial of service, or possibly execute arbitrary code.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
xorg-x11-server: buffer overflow in _GetCountedString() in xkb/xkb.c
vendor_redhat·2022-10-17·CVSS 5.5
CVE-2022-3550 [MEDIUM] CWE-119 xorg-x11-server: buffer overflow in _GetCountedString() in xkb/xkb.c
xorg-x11-server: buffer overflow in _GetCountedString() in xkb/xkb.c
A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051.
A flaw was found in the xorg-x11-server package. A buffer overflow can occur in the _GetCountedString function in xkb/xkb.c due to improper input validation, allowing for possible escalation of privileges, execution of arbitrary code, or a denial of service.
Statement: Xorg server does not run with root privileges in Red Hat Enterprise Linux 8 and 9, therefore Red Hat Enterprise Linux 8 and 9 have been rated wi
Debian
CVE-2022-3550: xorg-server - A vulnerability classified as critical was found in X.org Server. Affected by th...
vendor_debian·2022·CVSS 5.5
CVE-2022-3550 [MEDIUM] CVE-2022-3550: xorg-server - A vulnerability classified as critical was found in X.org Server. Affected by th...
A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051.
Scope: local
bookworm: resolved (fixed in 2:21.1.4-3)
bullseye: resolved (fixed in 2:1.20.11-1+deb11u3)
forky: resolved (fixed in 2:21.1.4-3)
sid: resolved (fixed in 2:21.1.4-3)
trixie: resolved (fixed in 2:21.1.4-3)
GHSA
GHSA-h54w-qqq6-jp69: A vulnerability classified as critical was found in X
ghsa_unreviewed·2022-10-17
CVE-2022-3550 [CRITICAL] CWE-119 GHSA-h54w-qqq6-jp69: A vulnerability classified as critical was found in X
A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051.
OSV
CVE-2022-3550: A vulnerability classified as critical was found in X
osv·2022-10-17·CVSS 8.8
CVE-2022-3550 [HIGH] CVE-2022-3550: A vulnerability classified as critical was found in X
A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cgit.freedesktop.org/xorg/xserver/commit/?id=11beef0b7f1ed290348e45618e5fa0d2bffcb72ehttps://lists.debian.org/debian-lts-announce/2022/11/msg00012.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QTPFVGYTOY4EWTJEBH3YGDTTU57FZAK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IOEDFBYPSE3EMVHTEFCVEJD2R2Y5F2A5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXZZ6JBDBVBYPDI6DUTY6N36GNW37YHK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X7W3NXSYK4P3XCZQBI3U6UWP4DPZIMRZ/https://security.gentoo.org/glsa/202305-30https://vuldb.com/?id.211051https://www.debian.org/security/2022/dsa-5278https://cgit.freedesktop.org/xorg/xserver/commit/?id=11beef0b7f1ed290348e45618e5fa0d2bffcb72ehttps://lists.debian.org/debian-lts-announce/2022/11/msg00012.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QTPFVGYTOY4EWTJEBH3YGDTTU57FZAK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IOEDFBYPSE3EMVHTEFCVEJD2R2Y5F2A5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXZZ6JBDBVBYPDI6DUTY6N36GNW37YHK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X7W3NXSYK4P3XCZQBI3U6UWP4DPZIMRZ/https://security.gentoo.org/glsa/202305-30https://vuldb.com/?id.211051https://www.debian.org/security/2022/dsa-5278
2022-10-17
Published