Incorrect Permission Assignment for Critical Resource Affecting mesa package, versions *


low

Snyk CVSS

    Attack Complexity Low

    Threat Intelligence

    EPSS 0.05% (21st percentile)
Expand this section
NVD
4.4 medium
Expand this section
SUSE
5.1 medium
Expand this section
Red Hat
5.1 medium

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-DEBIAN9-MESA-482124
  • published 10 Nov 2019
  • disclosed 5 Nov 2019

How to fix?

There is no fixed version for Debian:9 mesa.

NVD Description

Note: Versions mentioned in the description apply only to the upstream mesa package and not the mesa package as distributed by Debian. See How to fix? for Debian:9 relevant fixed versions and status.

An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared memory without any specific permissions to trigger this vulnerability.