PT-2020-5334 · Xorg+8 · Xorg-X11-Server+8
Jan-Niklas Sohn
·
Published
2020-08-25
·
Updated
2024-06-15
·
CVE-2020-14346
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
xorg-x11-server versions prior to 1.20.9
Description
The issue is related to an integer underflow in the X input extension protocol decoding in the X server, which may lead to arbitrary access of memory contents. This poses a threat to data confidentiality and integrity, as well as system availability. The vulnerability allows an attacker to access confidential data, compromise their integrity, and cause a denial of service.
Recommendations
For versions prior to 1.20.9, update to version 1.20.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the X server to minimize the risk of exploitation. Avoid using the vulnerable X input extension protocol until the issue is resolved.
Exploit
Fix
Integer Overflow
Integer Underflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Xorg-X11-Server