QID 354751
Date Published: 2023-02-28
QID 354751: Amazon Linux Security Advisory for xorg-x11-server : ALAS-2023-1689
a flaw was found in the xorg-x11-server.
The specific flaw exists within the handling of procxkbsetdeviceinfo requests.
The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer.
This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root. (
( CVE-2022-2320) a vulnerability was found in x.org.
This security flaw occurs because the xkbcopynames function left a dangling pointer to freed memory, resulting in out-of-bounds memory access on subsequent xkbgetkbdbyname requests.. this issue can lead to local privileges elevation on systems where the x server is running privileged and remote code execution for ssh x forwarding sessions. (
( CVE-2022-4283) a vulnerability was found in x.org.
This security flaw occurs becuase the swap handler for the xtestfakeinput request of the xtest extension may corrupt the stack if genericevents with lengths larger than 32 bytes are sent through a the xtestfakeinput request.
This issue can lead to local privileges elevation on systems where the x server is running privileged and remote code execution for ssh x forwarding sessions.
This issue does not affect systems where client and server use the same byte order. (
( CVE-2022-46340) a vulnerability was found in x.org.
This security flaw occurs because the handler for the xipassiveungrab request accesses out-of-bounds memory when invoked with a high keycode or button code.
This issue can lead to local privileges elevation on systems where the x server is running privileged and remote code execution for ssh x forwarding sessions. (
( CVE-2022-46344)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
- ALAS-2023-1689 -
alas.aws.amazon.com/ALAS-2023-1689.html
CVEs related to QID 354751
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS-2023-1689 | amazon linux |
|