CVE-2019-19520

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/12/2019
Last modified:
24/08/2020

Description

xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xenocara/lib/mesa/src/loader/loader.c mishandles dlopen.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:openbsd:openbsd:6.6:*:*:*:*:*:*:*