ZeroHour

CVE-2023-6377

CVSS 3.1
7.8 high
EPSS
2%p74
Published
()
Modified
Description

A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.

Vendors
redhatdebianx.orgtigervnc
Products
enterprise linux eus, debian linux, x server, xwayland, tigervnc
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.