Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2023-0494

A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote code execution for ssh X forwarding sessions.

  • Published: Mar 27, 2023
  • Updated: Apr 14, 2023
  • CVE: CVE-2023-0494
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.8
  • AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CWEs:

Software From Fixed in
x.org / x_server - 21.1.7
fedoraproject / fedora 36 36.x
fedoraproject / fedora 37 37.x
redhat / enterprise_linux_desktop 7.0 7.0.x
redhat / enterprise_linux_for_scientific_computing 7.0 7.0.x
redhat / enterprise_linux_server 7.0 7.0.x
redhat / enterprise_linux_for_power_little_endian 7.0 7.0.x
redhat / enterprise_linux_for_power_big_endian 7.0 7.0.x
redhat / enterprise_linux_for_ibm_z_systems 7.0 7.0.x
redhat / enterprise_linux 8.0 8.0.x
redhat / enterprise_linux 8.1 8.1.x
redhat / enterprise_linux_server_tus 8.2 8.2.x
redhat / enterprise_linux_server_aus 8.2 8.2.x
redhat / enterprise_linux_server_workstation 7.0 7.0.x
redhat / enterprise_linux_aus 8.4 8.4.x
redhat / enterprise_linux_server_tus 8.4 8.4.x
redhat / enterprise_linux_eus 8.4 8.4.x
redhat / enterprise_linux_server_update_services_for_sap_solutions 8.2 8.2.x
redhat / enterprise_linux_for_power_little_endian 8.0 8.0.x
redhat / enterprise_linux_for_ibm_z_systems_eus 8.4 8.4.x
redhat / enterprise_linux_for_ibm_z_systems 8.0 8.0.x
redhat / enterprise_linux_for_power_little_endian_eus 8.4 8.4.x
redhat / enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 8.1 8.1.x
redhat / enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 8.2 8.2.x
redhat / enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 8.4 8.4.x
redhat / enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 8.6 8.6.x
redhat / enterprise_linux_for_ibm_z_systems_eus 8.6 8.6.x
redhat / enterprise_linux_server_tus 8.6 8.6.x
redhat / enterprise_linux_eus 8.6 8.6.x
redhat / enterprise_linux_for_power_little_endian_eus 8.6 8.6.x
redhat / enterprise_linux 9.0 9.0.x
redhat / enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 9.0 9.0.x
redhat / enterprise_linux_for_power_little_endian 9.0 9.0.x
redhat / enterprise_linux_eus 9.0 9.0.x
redhat / enterprise_linux_aus 8.6 8.6.x