CVE-2023-5367
Severity
7.8HIGH
EPSS
0.1%
top 80.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 25
Latest updateOct 31
Description
A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation of privileges or denial of service.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages9 packages
Also affects: Debian Linux 11.0, 12.0, Fedora 37, 38, 39, Enterprise Linux 7.0, 8.0, 9.0, 7.0_ppc64
Patches
🔴Vulnerability Details
5CVEList
▶
📋Vendor Advisories
7Red Hat
▶