ZDI-CAN-14952: X.Org Server SwapCreateRegister Out-Of-Bounds Access Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of SwapCreateRegister requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-14952?
The severity of ZDI-CAN-14952 is critical as it allows local attackers to escalate privileges.
How do I fix ZDI-CAN-14952?
To fix ZDI-CAN-14952, update the X.Org Server to the latest version available that addresses this vulnerability.
Who is affected by ZDI-CAN-14952?
ZDI-CAN-14952 affects installations of the X.Org Server software.
What is the vulnerability type of ZDI-CAN-14952?
ZDI-CAN-14952 is a privilege escalation vulnerability.
What must an attacker do to exploit ZDI-CAN-14952?
An attacker must first execute low-privileged code on the target system to exploit ZDI-CAN-14952.