7.8

CVE-2022-2319

A flaw was found in the Xorg-x11-server. An out-of-bounds access issue can occur in the ProcXkbSetGeometry function due to improper validation of the request length.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
X.Org ≫ X Server Version 21.1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.37
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-1320 Improper Protection for Outbound Error Messages and Alert Signals

Untrusted agents can disable alerts about signal conditions exceeding limits or the response mechanism that handles such alerts.

https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/938
Patch
Third Party Advisory
https://gitlab.freedesktop.org/xorg/xserver/-/merge_requests/939
Patch
Third Party Advisory
https://lists.freedesktop.org/archives/xorg-announce/2022-July/003192.html
Patch
Third Party Advisory
https://security.gentoo.org/glsa/202210-30
Third Party Advisory
https://security.netapp.com/advisory/ntap-20221104-0003/
Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-22-964/
Third Party Advisory
VDB Entry