CVE-2023-6478
HIGHxorg-server - Info Disclosure
Title source: llmDescription
A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.
References (28)
... and 8 more
Scores
CVSS v3
7.6
EPSS
0.0121
EPSS Percentile
78.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Classification
CWE
CWE-190
Status
published
Affected Products (7)
x.org/x_server
< 21.1.10
x.org/xwayland
< 23.2.3
redhat/enterprise_linux_eus
debian/debian_linux
debian/debian_linux
debian/debian_linux
tigervnc/tigervnc
Timeline
Published
Dec 13, 2023
Tracked Since
Feb 18, 2026