Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-25697

Опубликовано: 09 нояб. 2020
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

A privilege escalation flaw was found in the Xorg-x11-server due to a lack of authentication for X11 clients. This flaw allows an attacker to take control of an X application by impersonating the server it is expecting to connect to.

Отчет

As per upstream, exploiting this flaw is non-trivial and it requires exact timing on the behalf of the attacker. Many graphical applications exit if their connection to the X server is lost, so a typical desktop session is either impossible or difficult to exploit. There is currently no upstream patch available for this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 7xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 8xorg-x11-serverWill not fix
Red Hat Enterprise Linux 9xorg-x11-serverAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-306
Дефект:
CWE-362
https://bugzilla.redhat.com/show_bug.cgi?id=1895295xorg-x11-server: local privilege escalation

EPSS

Процентиль: 20%
0.00063
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
больше 4 лет назад

A privilege escalation flaw was found in the Xorg-x11-server due to a lack of authentication for X11 clients. This flaw allows an attacker to take control of an X application by impersonating the server it is expecting to connect to.

CVSS3: 7
nvd
больше 4 лет назад

A privilege escalation flaw was found in the Xorg-x11-server due to a lack of authentication for X11 clients. This flaw allows an attacker to take control of an X application by impersonating the server it is expecting to connect to.

CVSS3: 7
debian
больше 4 лет назад

A privilege escalation flaw was found in the Xorg-x11-server due to a ...

suse-cvrf
больше 2 лет назад

Security update for xtrans

suse-cvrf
больше 2 лет назад

Security update for xtrans

EPSS

Процентиль: 20%
0.00063
Низкий

7 High

CVSS3