Vulnerability CVE-2020-14361: Information

Description

A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Severity: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Published: Sept. 15, 2020
Modified: Nov. 3, 2022
Error type identifier: CWE-191

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
xorg-serversisyphus1.20.9-alt121.1.13-alt1ALT-PU-2020-2670-1256796Fixed
xorg-serversisyphus_riscv641.20.14-alt121.1.13-alt1ALT-PU-2021-4696-1-Fixed
xorg-serverp101.20.9-alt11.20.14-alt13ALT-PU-2020-2670-1256796Fixed
xorg-serverp91.20.8-alt41.20.8-alt12ALT-PU-2020-2837-1258208Fixed
xorg-serverc10f11.20.9-alt11.20.14-alt12ALT-PU-2020-2670-1256796Fixed
xorg-serverc9f21.20.8-alt41.20.8-alt12ALT-PU-2020-2837-1258208Fixed
xorg-serverp111.20.9-alt121.1.13-alt1ALT-PU-2020-2670-1256796Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1869142
  • Issue Tracking
  • Third Party Advisory
https://lists.x.org/archives/xorg-announce/2020-August/003058.html
  • Mailing List
  • Patch
  • Vendor Advisory
USN-4488-2
  • Third Party Advisory
GLSA-202012-01
  • Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-1418/
  • Third Party Advisory
  • VDB Entry
    1. Configuration 1

      cpe:2.3:a:x.org:xorg-server:*:*:*:*:*:*:*:*
      End excliding
      1.20.9

      Configuration 2

      cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*

      cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*