ZeroHour

CVE-2024-0409

CVSS 3.1
7.8 high
EPSS
<1%p29
Published
()
Modified
Description

A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that overwrites the XSELINUX context.

Vendors
tigervncx.orgfedoraprojectredhat
Products
tigervnc, x server, xwayland, fedora, enterprise linux, enterprise linux desktop, enterprise linux for ibm z systems, enterprise linux for power big endian, enterprise linux for power little endian, enterprise linux for scientific computing, enterprise linux server, enterprise linux workstation
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.