NA

CVE-2023-24039

Published: 21/01/2023 Updated: 17/05/2024
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A stack-based buffer overflow in ParseColors in libXm in Common Desktop Environment 1.6 can be exploited by local low-privileged users via the dtprintinfo setuid binary to escalate their privileges to root on Solaris 10 systems. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opengroup common desktop environment 1.6

Vendor Advisories

Description<!---->A flaw was found in libXm, a library distributed by the motif package A specially crafted XPM file with long color strings can lead to a stack-based buffer overflow in the ParseColors function due to the unsafe use of the strcat function, resulting in privilege escalationA flaw was found in libXm, a library distributed by the mo ...