Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-14363

Опубликовано: 25 авг. 2020
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application compiled with libX11 to crash, or in some cases, result in arbitrary code execution. The highest threat from this flaw is to confidentiality, integrity as well as system availability.

Отчет

Xorg server does not run with root privileges in Red Hat Enterprise Linux 8. Therefore this flaw has been rated as having a moderate impact for Red Hat Enterprise Linux 8.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libX11Out of support scope
Red Hat Enterprise Linux 6libX11FixedRHSA-2020:494605.11.2020
Red Hat Enterprise Linux 7libX11FixedRHSA-2020:490804.11.2020
Red Hat Enterprise Linux 8egl-waylandFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libdrmFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libglvndFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libinputFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libwacomFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libX11FixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8mesaFixedRHSA-2021:180418.05.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190->CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1872473libX11: integer overflow leads to double free in locale handling

EPSS

Процентиль: 38%
0.00163
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 5 лет назад

An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application compiled with libX11 to crash, or in some cases, result in arbitrary code execution. The highest threat from this flaw is to confidentiality, integrity as well as system availability.

CVSS3: 7.8
nvd
почти 5 лет назад

An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application compiled with libX11 to crash, or in some cases, result in arbitrary code execution. The highest threat from this flaw is to confidentiality, integrity as well as system availability.

CVSS3: 7.8
debian
почти 5 лет назад

An integer overflow vulnerability leading to a double-free was found i ...

suse-cvrf
почти 5 лет назад

Security update for libX11

suse-cvrf
почти 5 лет назад

Security update for libX11

EPSS

Процентиль: 38%
0.00163
Низкий

7.8 High

CVSS3