CVE-2023-6478

HIGH EPSS 73.2%
Published Dec 13, 20232y ago · Modified Jun 23, 20266d ago
7.5 CVSS 3.1
High
Find Similar
Published Dec 13, 2023 2y ago
Last Modified Jun 23, 2026 6d ago

Description

A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.

CVSS Details

Base Score
7.5
Exploitability
3.9
Impact
3.6
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity None
Availability None

Threat Intelligence

EPSS Exploit Probability
73.2% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-190 Integer Overflow or Wraparound Numeric Error

Affected Products 17

VendorProductVersionRange
x.orgx_server* <21.1.10
redhatenterprise_linux6.0any
redhatenterprise_linux7.0any
redhatenterprise_linux8.0any
redhatenterprise_linux9.0any
x.orgxwayland* <23.2.3
redhatenterprise_linux8.0any
redhatenterprise_linux9.0any
redhatenterprise_linux_eus9.2any
debiandebian_linux10.0any
debiandebian_linux11.0any
debiandebian_linux12.0any
tigervnctigervnc*any
redhatenterprise_linux6.0any
redhatenterprise_linux7.0any
redhatenterprise_linux8.0any
redhatenterprise_linux9.0any

References 28

Remediation

  • gitlab.freedesktop.org https://gitlab.freedesktop.org/xorg/xserver/-/commit/14f480010a93ff962fef66a16412fafff81ad632
    Patch