Input validation error in xterm - CVE-2023-40359

 

Input validation error in xterm - CVE-2023-40359

Published: August 21, 2023


Vulnerability identifier: #VU79805
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-40359
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in ReGIS support. A local user can pass unexpected characters to the application and perform a denial of service (DoS) attack.


Affected software

xterm
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Basesystem Module
openSUSE Leap
xterm-bin
xterm-debugsource
xterm-bin-debuginfo
xterm

How to mitigate CVE-2023-40359

Install updates from vendor's website.

xterm - update to 380
xterm-bin - update to 330-150200.11.12.1
xterm-debugsource - update to 330-150200.11.12.1
xterm-bin-debuginfo - update to 330-150200.11.12.1
xterm - update to 330-150200.11.12.1

External References

Related Security Bulletins