Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-5367


A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation of privileges or denial of service.


Published

2023-10-25T20:15:18.323

Last Modified

2025-11-04T20:17:13.090

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-787
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application x.org x_server < 21.1.9 Yes
Application x.org xwayland < 23.2.2 Yes
Operating System redhat enterprise_linux 7.0 Yes
Operating System redhat enterprise_linux 8.0 Yes
Operating System redhat enterprise_linux 9.0 Yes
Operating System redhat enterprise_linux_desktop 7.0 Yes
Operating System redhat enterprise_linux_for_ibm_z_systems 7.0_s390x Yes
Operating System redhat enterprise_linux_for_power_big_endian 7.0_ppc64 Yes
Operating System redhat enterprise_linux_for_power_little_endian 7.0_ppc64le Yes
Operating System redhat enterprise_linux_for_scientific_computing 7.0 Yes
Operating System redhat enterprise_linux_server 7.0 Yes
Operating System redhat enterprise_linux_workstation 7.0 Yes
Operating System fedoraproject fedora 37 Yes
Operating System fedoraproject fedora 38 Yes
Operating System fedoraproject fedora 39 Yes
Operating System debian debian_linux 11.0 Yes
Operating System debian debian_linux 12.0 Yes

References