Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-14360

Опубликовано: 01 дек. 2020
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds access in the XkbSetMap function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

A flaw was found in the X.Org Server. An out-of-bounds access in the XkbSetMap function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

The Xorg server in Red Hat Enterprise Linux 8 does not run with root privileges, thus this flaw has been rated as having a moderate impact on that platform.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 6xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 7xorg-x11-serverFixedRHSA-2020:540814.12.2020
Red Hat Enterprise Linux 8egl-waylandFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libdrmFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libglvndFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libinputFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libwacomFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libX11FixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8mesaFixedRHSA-2021:180418.05.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1869139xorg-x11-server: Out-of-bounds access in XkbSetMap function

EPSS

Процентиль: 21%
0.00066
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 4 лет назад

A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds access in the XkbSetMap function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 7.8
nvd
больше 4 лет назад

A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds access in the XkbSetMap function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 7.8
debian
больше 4 лет назад

A flaw was found in the X.Org Server before version 1.20.10. An out-of ...

github
около 3 лет назад

A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds access in the XkbSetMap function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 7.8
fstec
больше 4 лет назад

Уязвимость функции XkbSetMap реализации сервера X Window System X.Org Server, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 21%
0.00066
Низкий

7.8 High

CVSS3