CVE-2023-24039

HIGH

Common Desktop Environment 1.6 - Buffer Overflow

Title source: llm
STIX 2.1

Description

A stack-based buffer overflow in ParseColors in libXm in Common Desktop Environment 1.6 can be exploited by local low-privileged users via the dtprintinfo setuid binary to escalate their privileges to root on Solaris 10 systems. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Scores

CVSS v3 7.8
EPSS 0.0029
EPSS Percentile 52.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Products (1)
opengroup/common_desktop_environment 1.6
Published Jan 21, 2023
Tracked Since Feb 18, 2026