A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.
References
Link Providers
http://www.openwall.com/lists/oss-security/2023/12/13/1 cve-icon
https://access.redhat.com/errata/RHSA-2023:7886 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:0006 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:0009 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:0010 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:0014 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:0015 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:0016 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:0017 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:0018 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:0020 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:2169 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:2170 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:2995 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2024:2996 cve-icon cve-icon
https://access.redhat.com/security/cve/CVE-2023-6478 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2253298 cve-icon cve-icon
https://gitlab.freedesktop.org/xorg/xserver/-/commit/14f480010a93ff962fef66a16412fafff81ad632 cve-icon cve-icon cve-icon
https://lists.debian.org/debian-lts-announce/2023/12/msg00008.html cve-icon
https://lists.fedoraproject.org/archives/list/[email protected]/message/6R63Z6GIWM3YUNZRCGFODUXLW3GY2HD6/ cve-icon
https://lists.fedoraproject.org/archives/list/[email protected]/message/7PP47YXKM5ETLCYEF6473R3VFCJ6QT2S/ cve-icon
https://lists.fedoraproject.org/archives/list/[email protected]/message/IFHV5KCQ2SVOD4QMCPZ5HC6YL44L7YJD/ cve-icon
https://lists.fedoraproject.org/archives/list/[email protected]/message/LJDFWDB7EQVZA45XDP7L5WRSRWS6RVRR/ cve-icon
https://lists.x.org/archives/xorg-announce/2023-December/003435.html cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2023-6478 cve-icon
https://security.gentoo.org/glsa/202401-30 cve-icon
https://security.netapp.com/advisory/ntap-20240125-0003/ cve-icon
https://www.cve.org/CVERecord?id=CVE-2023-6478 cve-icon
https://www.debian.org/security/2023/dsa-5576 cve-icon
History

Fri, 22 Nov 2024 12:00:00 +0000


Mon, 16 Sep 2024 16:30:00 +0000


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2023-12-13T06:27:41.017Z

Updated: 2024-11-23T02:52:01.579Z

Reserved: 2023-12-04T06:40:47.239Z

Link: CVE-2023-6478

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-12-13T07:15:31.213

Modified: 2024-11-21T08:43:55.953

Link: CVE-2023-6478

cve-icon Redhat

Severity : Important

Publid Date: 2023-12-13T00:00:00Z

Links: CVE-2023-6478 - Bugzilla