CVE-2023-43787: Libx11: integer overflow in xcreateimage() leading to a heap overflow
A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges.
Other sources
A vulnerability was found in libX11 where the vulnerability exists due to integer overflow within the XCreateImage() function, a local user can trigger integer overflow and execute arbitrary code with elevated privileges.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-43787?
CVE-2023-43787 is a vulnerability in the libX11 library that allows an attacker to trigger a heap overflow through an integer overflow in the XCreateImage() function.
How severe is CVE-2023-43787?
CVE-2023-43787 has a severity rating of high.
Which software versions are affected by CVE-2023-43787?
Versions 1.8.7 of libX11 (Ubuntu) and versions up to 1.8.7 (Ubuntu) are affected by CVE-2023-43787.
How do I fix CVE-2023-43787?
To fix CVE-2023-43787, upgrade to version 1.8.7 (Ubuntu) or later, or apply the recommended patches for your specific Ubuntu or Debian distribution.
Where can I find more information about CVE-2023-43787?
You can find more information about CVE-2023-43787 in the CVE entry at [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-43787](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-43787) and the Ubuntu security notices at [https://ubuntu.com/security/notices/USN-6407-1](https://ubuntu.com/security/notices/USN-6407-1) and [https://ubuntu.com/security/notices/USN-6408-1](https://ubuntu.com/security/notices/USN-6408-1).