CVE-2023-24039 describes a stack-based buffer overflow in the ParseColors function of libXm within Common Desktop Environment 1.6. This vulnerability specifically impacts Solaris 10 systems, allowing local low-privileged users to escalate privileges to root via the dtprintinfo setuid binary. With a CVSS score of 7.8 (High), it presents a significant risk for affected systems, enabling high impact on confidentiality, integrity, and availability. However, this vulnerability affects products no longer supported by their maintainer, and there is currently no public exploit code, Metasploit modules, or community discussion indicating active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.6CPE matchmatch criteria | cpe:2.3:a:opengroup:common_desktop_environment:1.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.