CVE-2018-14599Off-by-one Error in Libx11

Severity
9.8CRITICALNVD
EPSS
1.7%
top 17.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 24
Latest updateMay 13

Description

An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unspecified other impact.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

Also affects: Debian Linux 8.0, Fedora 28, Ubuntu Linux 12.04, 14.04, 16.04, 18.04

Patches

🔴Vulnerability Details

4
GHSA
GHSA-4q9q-728x-j7v5: An issue was discovered in libX11 through 12022-05-13
OSV
libx11 vulnerabilities2018-08-30
OSV
CVE-2018-14599: An issue was discovered in libX11 through 12018-08-24
CVEList
CVE-2018-14599: An issue was discovered in libX11 through 12018-08-24

📋Vendor Advisories

4
Ubuntu
libx11 vulnerabilities2018-08-30
Ubuntu
libx11 vulnerabilities2018-08-30
Red Hat
libX11: Off-by-one error in XListExtensions in ListExt.c2018-08-21
Debian
CVE-2018-14599: libx11 - An issue was discovered in libX11 through 1.6.5. The function XListExtensions in...2018

💬Community

2
Bugzilla
CVE-2018-14599 libX11: off-by-one error in XListExtensions in ListExt.c [fedora-all]2018-08-28
Bugzilla
CVE-2018-14599 libX11: Off-by-one error in XListExtensions in ListExt.c2018-08-28
CVE-2018-14599 — Off-by-one Error in X.org Libx11 | cvebase