USN-6555-1
Dashboard / Vulnerabilities / USN-6555-1
USN-6555-1
Summary: xorg-server, xwayland vulnerabilities
Details: Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled XKB button actions. An attacker could possibly use this issue to cause the X Server to crash, execute arbitrary code, or escalate privileges. (CVE-2023-6377) Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled memory when processing the RRChangeOutputProperty and RRChangeProviderProperty APIs. An attacker could possibly use this issue to cause the X Server to crash, or obtain sensitive information. (CVE-2023-6478)
References: https://ubuntu.com/security/notices/USN-6555-1, https://ubuntu.com/security/CVE-2023-6377, https://ubuntu.com/security/CVE-2023-6478
Affected packages
Package
Name: xorg-server
Purl: pkg:deb/ubuntu/xorg-server@2:1.20.13-1ubuntu1~20.04.12?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
