vulnerability
FreeBSD: VID-848bdd06-f93a-11eb-9f7d-206a8a720317 (CVE-2020-2696): x11/cde -- Local privilege escalation via CDE dtsession
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:L/AC:L/Au:N/C:C/I:C/A:C) | Aug 9, 2021 | Nov 4, 2022 | Dec 10, 2025 |
Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Aug 9, 2021
Added
Nov 4, 2022
Modified
Dec 10, 2025
Description
Marco Ivaldi (marco.ivaldi () mediaservice net) reports: A buffer overflow in the CheckMonitor() function in the Common Desktop Environment 2.3.1 and earlier and 1.6 and earlier, as distributed with Oracle Solaris 10 1/13 (Update 11) and earlier, allows local users to gain root privileges via a long palette name passed to dtsession in a malicious .Xdefaults file.
Solution
freebsd-upgrade-package-cde
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.