News: 0001502472

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Local Privilege Escalation Vulnerability Affecting X.Org Server For 18 Years

([X.Org] 5 Hours Ago CVE-2024-9632)


CVE-2024-9632 was made public today as the latest security vulnerability affecting the X.Org Server. The CVE-2024-9632 security issue has been present in the codebase now for 18 years and can lead to local privilege escalation.

Introduced in the X.Org Server 1.1.1 release back in 2006, CVE-2024-9632 affects the X.Org Server as well as XWayland too. By providing a modified bitmap to the X.Org Server, a heap-based buffer overflow privilege escalation can occur.

This security issue is within _XkbSetCompatMap() and stems from not updating the heap size properly and can lead to local privilege escalation if the server is run as root or as a remote code execution with X11 over SSH.

The X.Org security advisory announcement can be read on [1]the mailing list . The X.Org Server 21.1.4 and XWayland 24.1.4 releases fix the issue, which was discovered by the Trend Micro Zero Day Initiative. Trend Micro continues uncovering many X.Org security vulnerabilities over the years.



[1] https://lists.x.org/archives/xorg-announce/2024-October/003545.html



chuckula

Errinwright

t1r0nama

bacteriamanicure

tildearrow

Danny3

kpedersen

Nocifer

Artim

When users see one GUI as beautiful,
other user interfaces become ugly.
When users see some programs as winners,
other programs become lossage.

Pointers and NULLs reference each other.
High level and assembler depend on each other.
Double and float cast to each other.
High-endian and low-endian define each other.
While and until follow each other.

Therefore the Guru
programs without doing anything
and teaches without saying anything.
Warnings arise and he lets them come;
processes are swapped and he lets them go.
He has but doesn't possess,
acts but doesn't expect.
When his work is done, he deletes it.
That is why it lasts forever.