CVE-2023-45924
Severity CVSS v4.0:
Pending analysis
Type:
CWE-121
Stack-based Buffer Overflow
Publication date:
27/03/2024
Last modified:
04/11/2025
Description
libglxproto.c in OpenGL libglvnd bb06db5a was discovered to contain a segmentation violation via the function glXGetDrawableScreen(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
References to Advisories, Solutions, and Tools
- http://seclists.org/fulldisclosure/2024/Jan/52
- https://gitlab.freedesktop.org/glvnd/libglvnd/-/issues/242
- https://gitlab.freedesktop.org/glvnd/libglvnd/-/merge_requests/295
- http://packetstormsecurity.com/files/176807/libglvnd-bb06db5a-Buffer-Overflow-Null-Pointer.html
- http://seclists.org/fulldisclosure/2024/Jan/52
- https://gitlab.freedesktop.org/glvnd/libglvnd/-/issues/242
- https://gitlab.freedesktop.org/glvnd/libglvnd/-/merge_requests/295



