Vulnerability Description
Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mesa3D | Mesa | 23.0.4 |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2024/Jan/47Mailing ListThird Party Advisory
- https://gitlab.freedesktop.org/mesa/mesa/-/issues/9858ExploitVendor Advisory
- http://packetstormsecurity.com/files/176802/Mesa-23.0.4-Buffer-Overflow.html
- http://seclists.org/fulldisclosure/2024/Jan/47Mailing ListThird Party Advisory
- https://gitlab.freedesktop.org/mesa/mesa/-/issues/9858ExploitVendor Advisory
FAQ
What is CVE-2023-45919?
CVE-2023-45919 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an...
How severe is CVE-2023-45919?
CVE-2023-45919 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-45919?
Check the references section above for vendor advisories and patch information. Affected products include: Mesa3D Mesa.