Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-14361

Опубликовано: 25 авг. 2020
Источник: redhat
CVSS3: 7.8

Описание

A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

A flaw was found in X.Org Server. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

Xorg server does not run with root privileges in Red Hat Enterprise Linux 8, therefore this flaw has been rated as having moderate impact for Red Hat Enterprise linux 8.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 9xorg-x11-serverNot affected
Red Hat Enterprise Linux 6xorg-x11-serverFixedRHSA-2020:495305.11.2020
Red Hat Enterprise Linux 7xorg-x11-serverFixedRHSA-2020:491004.11.2020
Red Hat Enterprise Linux 8egl-waylandFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libdrmFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libglvndFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libinputFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libwacomFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libX11FixedRHSA-2021:180418.05.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-191
https://bugzilla.redhat.com/show_bug.cgi?id=1869142xorg-x11-server: XkbSelectEvents integer underflow privilege escalation vulnerability

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 5 лет назад

A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 7.8
nvd
почти 5 лет назад

A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 7.8
debian
почти 5 лет назад

A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Int ...

CVSS3: 7.8
github
около 3 лет назад

A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 5.9
fstec
почти 5 лет назад

Уязвимость функции SProcXkbSelectEvents сервера X Window System Xorg-server, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

7.8 High

CVSS3