Name
CVE-2023-6478
Description
A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.
Published Date
Updated Date
Workaround
-
Advisories
https://access.redhat.com/errata/RHSA-2023:7886Vendor Advisory
https://access.redhat.com/security/cve/CVE-2023-6478Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2253298Issue Tracking
https://access.redhat.com/errata/RHSA-2023:7886Vendor Advisory
https://access.redhat.com/security/cve/CVE-2023-6478Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2253298Issue Tracking
Analysis#
Vulnerability Ratings#
7.6
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components#
Resolved with patches#
xserver-xorg (yocto:kirkstone)
#
Title
Author
Resolve
1
randr: avoid integer truncation in length check of
Peter Hutterer <peter.hutterer@who-t.net>
CVE-2023-6478
xwayland (yocto:kirkstone)
#
Title
Author
Resolve
1
randr: avoid integer truncation in length check of
Peter Hutterer <peter.hutterer@who-t.net>
CVE-2023-6478