CVE-2023-5367

CWE-787Out-of-bounds Write13 documents9 sources
Severity
7.8HIGH
EPSS
0.1%
top 80.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 25
Latest updateOct 31

Description

A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation of privileges or denial of service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages9 packages

Debianxorg-server< 2:1.20.11-1+deb11u8+3
Ubuntuxorg-server< 2:1.20.13-1ubuntu1~20.04.9+4
NVDx.org/x_server< 21.1.9
NVDx.org/xwayland< 23.2.2

Also affects: Debian Linux 11.0, 12.0, Fedora 37, 38, 39, Enterprise Linux 7.0, 8.0, 9.0, 7.0_ppc64

Patches

🔴Vulnerability Details

5
OSV
xorg-server vulnerabilities2023-10-31
GHSA
GHSA-q38f-wwqq-rr3v: A out-of-bounds write flaw was found in the xorg-x11-server2023-10-25
OSV
xorg-server, xwayland vulnerabilities2023-10-25
CVEList
Xorg-x11-server: out-of-bounds write in xichangedeviceproperty/rrchangeoutputproperty2023-10-25
OSV
CVE-2023-5367: A out-of-bounds write flaw was found in the xorg-x11-server2023-10-25

📋Vendor Advisories

7
Ubuntu
X.Org X Server vulnerabilities2023-10-31
BSD
OpenBSD 7.3 Errata 018: SECURITY FIX2023-10-25
Ubuntu
X.Org X Server vulnerabilities2023-10-25
Red Hat
xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty2023-10-25
BSD
OpenBSD 7.4 Errata 001: SECURITY FIX2023-10-25