Input validation error in xterm - CVE-2023-40359
Published: August 21, 2023
Vulnerability identifier: #VU79805
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-40359
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in ReGIS support. A local user can pass unexpected characters to the application and perform a denial of service (DoS) attack.
Affected software
xterm
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Basesystem Module
openSUSE Leap
xterm-bin
xterm-debugsource
xterm-bin-debuginfo
xterm
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Basesystem Module
openSUSE Leap
xterm-bin
xterm-debugsource
xterm-bin-debuginfo
xterm
How to mitigate CVE-2023-40359
Install updates from vendor's website.
xterm - update to 380
xterm-bin - update to 330-150200.11.12.1
xterm-debugsource - update to 330-150200.11.12.1
xterm-bin-debuginfo - update to 330-150200.11.12.1
xterm - update to 330-150200.11.12.1
xterm-bin - update to 330-150200.11.12.1
xterm-debugsource - update to 330-150200.11.12.1
xterm-bin-debuginfo - update to 330-150200.11.12.1
xterm - update to 330-150200.11.12.1