Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-25712

Опубликовано: 01 дек. 2020
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

A flaw was found in xorg-x11-server. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

The Xorg server in Red Hat Enterprise Linux 8 does not run with root privileges, thus this flaw has been rated as having a moderate impact on that platform.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 6xorg-x11-serverOut of support scope
Red Hat Enterprise Linux 7xorg-x11-serverFixedRHSA-2020:540814.12.2020
Red Hat Enterprise Linux 8egl-waylandFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libdrmFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libglvndFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libinputFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libwacomFixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8libX11FixedRHSA-2021:180418.05.2021
Red Hat Enterprise Linux 8mesaFixedRHSA-2021:180418.05.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1887276xorg-x11-server: XkbSetDeviceInfo heap-based buffer overflow privilege escalation vulnerability

EPSS

Процентиль: 25%
0.00081
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 4 лет назад

A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 7.8
nvd
больше 4 лет назад

A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 7.8
debian
больше 4 лет назад

A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer over ...

redos
почти 3 года назад

Уязвимость caribou

github
около 3 лет назад

A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

EPSS

Процентиль: 25%
0.00081
Низкий

7.8 High

CVSS3

Уязвимость CVE-2020-25712