First published: Mon Oct 17 2022(Updated: )
A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211051.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/xorg-server | <=2:1.20.4-1+deb10u4 | 2:1.20.4-1+deb10u9 2:1.20.11-1+deb11u6 2:21.1.7-3 2:21.1.8-1 |
debian/xwayland | 2:22.1.9-1 2:23.2.1-1 | |
X.Org X Server | <21.1.6 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-3550 is high, with a severity value of 8.8.
The affected software versions include X.org Server 2:1.20.4-1+deb10u9, 2:1.20.11-1+deb11u6, 2:21.1.7-3, and 2:21.1.8-1.
To fix CVE-2022-3550, it is recommended to apply the available patch for the X.org Server.
You can find more information about CVE-2022-3550 on the following references: https://vuldb.com/?id.211051, https://cgit.freedesktop.org/xorg/xserver/commit/?id=11beef0b7f1ed290348e45618e5fa0d2bffcb72e, and https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2140699.
The Common Weakness Enumeration (CWE) associated with CVE-2022-3550 is CWE-119 and CWE-120.