Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-14347

Опубликовано: 31 июл. 2020
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.

A flaw was found in the way the Xserver memory was not properly initialized. This issue leak parts of server memory to the X client. In cases where the Xorg server runs with elevated privileges, this flaw results in a possible ASLR bypass.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 6xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 9xorg-x11-serverAffected
Red Hat Enterprise Linux 7xorg-x11-serverFixedRHSA-2020:540814.12.2020
Red Hat Enterprise Linux 8egl-waylandFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libdrmFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libglvndFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libinputFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libwacomFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libX11FixedRHSA-2021:180418.05.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-665
https://bugzilla.redhat.com/show_bug.cgi?id=1862258xorg-x11-server: Leak of uninitialized heap memory from the X server to clients in AllocatePixmap of dix/pixmap.c

EPSS

Процентиль: 3%
0.00018
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 5 лет назад

A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.

CVSS3: 5.5
nvd
почти 5 лет назад

A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.

CVSS3: 5.5
debian
почти 5 лет назад

A flaw was found in the way xserver memory was not properly initialize ...

CVSS3: 5.5
github
около 3 лет назад

A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.

CVSS3: 5.3
fstec
почти 5 лет назад

Уязвимость сервера X Window System Xorg-server, связанная с некорректной инициализацией памяти, позволяющая нарушителю вызвать утечку части серверной памяти для клиента Xorg-server

EPSS

Процентиль: 3%
0.00018
Низкий

5.5 Medium

CVSS3