cbcvebase.
CVE-2023-6478
published 2023-12-13

CVE-2023-6478: A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.

Affected

21 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianxorg-server< xorg-server 2:21.1.7-3+deb12u3 (bookworm)xorg-server 2:21.1.7-3+deb12u3 (bookworm)
debianxwayland< xorg-server 2:21.1.7-3+deb12u3 (bookworm)xorg-server 2:21.1.7-3+deb12u3 (bookworm)
msrccbl2_xorg-x11-server_1.20.10-5_on_cbl_mariner_2.0
redhatenterprise_linux_eus
x.orgx_server< 21.1.1021.1.10
x.orgxorg-server>= 0 < 2:1.20.11-1+deb11u92:1.20.11-1+deb11u9
x.orgxorg-server>= 0 < 2:21.1.7-3+deb12u32:21.1.7-3+deb12u3
x.orgxorg-server>= 0 < 2:21.1.10-12:21.1.10-1
x.orgxorg-server>= 0 < 2:21.1.10-12:21.1.10-1
x.orgxorg-server>= 0 < 2:1.20.13-1ubuntu1~20.04.122:1.20.13-1ubuntu1~20.04.12
x.orgxorg-server>= 0 < 2:21.1.4-2ubuntu1.7~22.04.52:21.1.4-2ubuntu1.7~22.04.5
x.orgxorg-server>= 0 < 2:1.15.1-0ubuntu2.11+esm92:1.15.1-0ubuntu2.11+esm9
x.orgxorg-server>= 0 < 2:1.18.4-0ubuntu0.12+esm82:1.18.4-0ubuntu0.12+esm8
x.orgxorg-server>= 0 < 2:1.19.6-1ubuntu4.15+esm32:1.19.6-1ubuntu4.15+esm3
x.orgxwayland< 23.2.323.2.3
x.orgxwayland>= 0 < 2:23.2.3-12:23.2.3-1
x.orgxwayland>= 0 < 2:23.2.3-12:23.2.3-1
x.orgxwayland>= 0 < 2:22.1.1-1ubuntu0.92:22.1.1-1ubuntu0.9

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.8HIGH