Vulnerability CVE-2022-46344: Information
Description
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a length-validation issues, resulting in out-of-bounds memory reads and potential information disclosure. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
Severity: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
xorg-server | sisyphus_e2k | 1.20.14-alt8.E2K.1 | 21.1.3-alt1.E2K.1 | ALT-PU-2023-3913-1 | - | Fixed |
xorg-server | p10 | 1.20.14-alt6 | 1.20.14-alt12 | ALT-PU-2022-3399-1 | 311677 | Fixed |
xorg-server | p10_e2k | 1.20.14-alt8.E2K.2 | 1.20.14-alt9.E2K.1 | ALT-PU-2023-6819-1 | - | Fixed |
xorg-server | p9 | 1.20.8-alt10 | 1.20.8-alt12 | ALT-PU-2023-7278-2 | 334512 | Fixed |
xorg-server | c10f1 | 1.20.14-alt6 | 1.20.14-alt12 | ALT-PU-2022-3399-1 | 311677 | Fixed |
xorg-server | c9f2 | 1.20.8-alt12 | 1.20.8-alt12 | ALT-PU-2024-3261-2 | 341756 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://access.redhat.com/security/cve/CVE-2022-46344 |
|
https://bugzilla.redhat.com/show_bug.cgi?id=2151760 |
|
DSA-5304 |
|
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z67QC4C3I2FI2WRFIUPEHKC36J362MLA/ |
|
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5NELB7YDWRABYYBG4UPTHRBDTKJRV5M2/ |
|
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DXDF2O5PPLE3SVAJJYUOSAD5QZ4TWQ2G/ |
|
https://security.gentoo.org/glsa/202305-30 | |
http://www.openwall.com/lists/oss-security/2023/12/13/1 |