vulnerability

FreeBSD: VID-848bdd06-f93a-11eb-9f7d-206a8a720317 (CVE-2020-2696): x11/cde -- Local privilege escalation via CDE dtsession

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Aug 9, 2021
Added
Nov 4, 2022
Modified
Dec 10, 2025

Description

Marco Ivaldi (marco.ivaldi () mediaservice net) reports: A buffer overflow in the CheckMonitor() function in the Common Desktop Environment 2.3.1 and earlier and 1.6 and earlier, as distributed with Oracle Solaris 10 1/13 (Update 11) and earlier, allows local users to gain root privileges via a long palette name passed to dtsession in a malicious .Xdefaults file.

Solution

freebsd-upgrade-package-cde
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.