An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared memory without any specific permissions to trigger this vulnerability.
References
Link | Resource |
---|---|
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00037.html | Mailing List Third Party Advisory |
https://gitlab.freedesktop.org/mesa/mesa/-/commit/02c3dad0f3b4d26e0faa5cc51d06bc50d693dcdc | Patch Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2019/11/msg00013.html | Mailing List Third Party Advisory |
https://lists.freedesktop.org/pipermail/mesa-dev/2019-October/223704.html | Mailing List Patch Third Party Advisory |
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0857 | Exploit Third Party Advisory |
https://usn.ubuntu.com/4271-1/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
21 Jun 2022, 19:23
Type | Values Removed | Values Added |
---|---|---|
References | (UBUNTU) https://usn.ubuntu.com/4271-1/ - Third Party Advisory | |
References | (MISC) https://lists.freedesktop.org/pipermail/mesa-dev/2019-October/223704.html - Mailing List, Patch, Third Party Advisory | |
References | (MISC) https://gitlab.freedesktop.org/mesa/mesa/-/commit/02c3dad0f3b4d26e0faa5cc51d06bc50d693dcdc - Patch, Third Party Advisory | |
References | (MLIST) https://lists.debian.org/debian-lts-announce/2019/11/msg00013.html - Mailing List, Third Party Advisory | |
References | (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00037.html - Mailing List, Third Party Advisory | |
CPE | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:* |
Information
Published : 2019-11-05 22:15
Updated : 2024-02-04 20:39
NVD link : CVE-2019-5068
Mitre link : CVE-2019-5068
CVE.ORG link : CVE-2019-5068
JSON object : View
Products Affected
mesa3d
- mesa
canonical
- ubuntu_linux
debian
- debian_linux
opensuse
- leap