Use After Free Affecting xorg-server package, versions <2:1.20.4-1+deb10u10


0.0
medium

Snyk CVSS

    Attack Complexity High
    Availability High

    Threat Intelligence

    EPSS 0.04% (10th percentile)
Expand this section
NVD
4.7 medium
Expand this section
SUSE
5.1 medium
Expand this section
Red Hat
4.7 medium

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-DEBIAN10-XORGSERVER-6035094
  • published 25 Oct 2023
  • disclosed 25 Oct 2023

How to fix?

Upgrade Debian:10 xorg-server to version 2:1.20.4-1+deb10u10 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream xorg-server package and not the xorg-server package as distributed by Debian. See How to fix? for Debian:10 relevant fixed versions and status.

A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.