A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.
{ "vanir_signatures": [ { "signature_version": "v1", "signature_type": "Line", "target": { "file": "randr/rrproperty.c" }, "deprecated": false, "digest": { "line_hashes": [ "200756410113107532464116263241543496755", "159544367717622752330049412082583520851", "34752593602938598555778189773410832668", "130121146301272206283198864372898575079" ], "threshold": 0.9 }, "id": "CVE-2023-6478-58fda048", "source": "https://gitlab.freedesktop.org/xorg/xserver@14f480010a93ff962fef66a16412fafff81ad632" }, { "signature_version": "v1", "signature_type": "Line", "target": { "file": "randr/rrproviderproperty.c" }, "deprecated": false, "digest": { "line_hashes": [ "200756410113107532464116263241543496755", "159544367717622752330049412082583520851", "18962900824281389668529133635982324986", "144981788402403718693218915965340486412" ], "threshold": 0.9 }, "id": "CVE-2023-6478-642a392c", "source": "https://gitlab.freedesktop.org/xorg/xserver@14f480010a93ff962fef66a16412fafff81ad632" } ] }