
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability was identified in X.org Server affecting the file hw/xquartz/X11Controller.m. The issue was discovered in July 2022 and was assigned CVE-2022-3553. The vulnerability affects the XQuartz component, which is part of the X Window System server implementation (Debian Tracker, Gentoo Security).
The vulnerability stems from a potential crash condition when editing the Application menu due to mutating immutable arrays in the XQuartz component. The specific issue occurs in the X11Controller.m file where there was improper handling of array mutations, which could lead to an exception with the message '-[__NSCFArray replaceObjectAtIndex:withObject:]: mutating method sent to immutable object' (Freedesktop Commit).
The vulnerability could result in a crash of the X server when attempting to edit the Application menu in XQuartz, potentially disrupting the graphical user interface functionality (Freedesktop Commit).
The issue has been fixed in newer versions of the X.org Server. Users should upgrade to the patched versions. For example, Gentoo users should upgrade to xorg-server version 21.1.8 or later (Gentoo Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."