VDB
BDU%3A2024-00639
BDU%3A2024-00639
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость компонента Privates Handler реализации сервера X Window System X.Org Server, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 8 | |
| Red Hat | Red Hat Enterprise Linux 8 | 0:21.1.3-15.el8 |
| 21.1.0 | ||
| Red Hat | Red Hat Enterprise Linux 8 | 0:1.20.11-22.el8 |
| Red Hat | Red Hat Enterprise Linux 6 | |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 6 | |
| Red Hat Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», АО «ИВК», АО «НТЦ ИТ РОСА», Fedora Project, X.Org Foundation | Red Hat Enterprise Linux, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), Альт 8 СП (запись в едином реестре российских программ №4305), РОСА Кобальт (запись в едином реестре российских программ №1999), Fedora, РОСА ХРОМ (запись в едином реестре российских программ №1607), АЛЬТ СП 10, X.Org Server, XWayland | |
| Red Hat | Red Hat Enterprise Linux 9 | 0:22.1.9-5.el9 |
| Red Hat | Red Hat Enterprise Linux 7 | 0:1.20.4-27.el7_9 |
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.20.11-24.el9 |
| Red Hat | Red Hat Enterprise Linux 9 |
Timeline
- Jan 18, 2024 CVE Published
- Feb 12, 2024 PoC Published
- Mar 5, 2025 CVE Updated
- Jun 2, 2026 Distribution Patch
- Jun 2, 2026 Distribution Patch
- Jun 2, 2026 Distribution Patch
- Jun 2, 2026 Distribution Patch
- Jun 2, 2026 Distribution Patch
- Jun 2, 2026 Security Advisory
- Jun 2, 2026 Security Advisory
- Jun 2, 2026 Security Advisory
- Jun 2, 2026 Security Advisory
References
- https://access.redhat.com/security/cve/CVE-2024-0409 url
- https://bugzilla.redhat.com/show_bug.cgi?id=2257690 url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5J4H7CH565ALSZZYKOJFYDA5KFLG6NUK/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EJBMCWQ54R6ZL3MYU2D2JBW6JMZL7BQW/ url
- https://lists.x.org/archives/xorg/2024-January/061525.html url
- https://gitlab.freedesktop.org/xorg/xserver/-/commit/9e2ecb2af8302dedc49cb6a63ebe063c58a9e7e3 url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://abf.rosalinux.ru/advisories/ROSA-SA-2024-2351 url
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2576 url
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2575 url
- RHSA-2024:0320 vendor-advisory
- RHSA-2024:2169 vendor-advisory
- RHSA-2024:2170 vendor-advisory
- RHSA-2024:2995 vendor-advisory
- RHSA-2024:2996 vendor-advisory
- https://lists.debian.org/debian-lts-announce/2024/01/msg00016.html url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IZ75X54CN4IFYMIV7OK3JVZ57FHQIGIC/ url
- https://security.gentoo.org/glsa/202401-30 url
- https://security.netapp.com/advisory/ntap-20240307-0006/ url