ZDI-CAN-22561: ZDI-24-009: X.Org Server RRChangeOutputProperty Integer Overflow Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of X.Org Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2023-6478.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22561?
The severity of ZDI-CAN-22561 is classified as high due to the potential for local attackers to disclose sensitive information.
How do I fix ZDI-CAN-22561?
To fix ZDI-CAN-22561, you should update the affected X.Org Server to a version that includes the necessary security patches.
What software is affected by ZDI-CAN-22561?
ZDI-CAN-22561 affects installations of X.Org Server provided by The X.Org Foundation.
Who can exploit the vulnerability ZDI-CAN-22561?
ZDI-CAN-22561 can be exploited by local attackers who have the ability to execute low-privileged code on the target system.
What kind of information can be disclosed by exploiting ZDI-CAN-22561?
Exploitation of ZDI-CAN-22561 can lead to the disclosure of sensitive information stored in affected installations.