CVE-2023-5574
25.10.2023, 20:15
A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| x.org | x_server | 1.13.0 ≤ |
| redhat | enterprise_linux | 7.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| xorg |
| ||||||||||||||||||
| xorg-hwe-16.04 |
| ||||||||||||||||||
| xorg-hwe-18.04 |
| ||||||||||||||||||
| xorg-server |
| ||||||||||||||||||
| xorg-server-hwe-16.04 |
| ||||||||||||||||||
| xorg-server-hwe-18.04 |
| ||||||||||||||||||
| xorg-server-lts-utopic |
| ||||||||||||||||||
| xorg-server-lts-vivid |
| ||||||||||||||||||
| xorg-server-lts-wily |
| ||||||||||||||||||
| xorg-server-lts-xenial |
| ||||||||||||||||||
| xwayland |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| xorg-x11-server |
| ||||||||||||||||||||||||||||||||||||
| xorg-x11-server-Xvfb |
| ||||||||||||||||||||||||||||||||||||
| xorg-x11-server-extra |
| ||||||||||||||||||||||||||||||||||||
| xorg-x11-server-sdk |
| ||||||||||||||||||||||||||||||||||||
| xorg-x11-server-wayland |
| ||||||||||||||||||||||||||||||||||||
| xwayland |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| tigervnc |
| ||
| tigervnc-icons |
| ||
| tigervnc-license |
| ||
| tigervnc-selinux |
| ||
| tigervnc-server |
| ||
| tigervnc-server-minimal |
| ||
| tigervnc-server-module |
|
Common Weakness Enumeration
References