CVE-2020-14346
published 2020-09-15CVE-2020-14346: A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.63%
46.5th percentile
A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | xorg-server | < xorg-server 2:1.20.9-1 (bookworm) | xorg-server 2:1.20.9-1 (bookworm) |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| x.org | x_server | < 1.20.9 | 1.20.9 |
| x.org | xorg-server | >= 0 < 2:1.20.9-1 | 2:1.20.9-1 |
| x.org | xorg-server | >= 0 < 2:1.20.9-1 | 2:1.20.9-1 |
| x.org | xorg-server | >= 0 < 2:1.20.9-1 | 2:1.20.9-1 |
| x.org | xorg-server | >= 0 < 2:1.20.9-1 | 2:1.20.9-1 |
| x.org | xorg-server | >= 0 < 2:1.18.4-0ubuntu0.9 | 2:1.18.4-0ubuntu0.9 |
| x.org | xorg-server | >= 0 < 2:1.19.6-1ubuntu4.5 | 2:1.19.6-1ubuntu4.5 |
| x.org | xorg-server | >= 0 < 2:1.20.8-2ubuntu2.3 | 2:1.20.8-2ubuntu2.3 |
| x.org | xorg-server | >= 0 < 2:1.15.1-0ubuntu2.11+esm2 | 2:1.15.1-0ubuntu2.11+esm2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.Org X Server vulnerabilities
vendor_ubuntu·2020-09-09·CVSS 7.8
CVE-2020-14345 [HIGH] X.Org X Server vulnerabilities
Title: X.Org X Server vulnerabilities
Summary: Several security issues were fixed in X.Org X Server.
USN-4488-1 fixed several vulnerabilities in X.Org. This update provides
the corresponding update and also the update from USN-4490-1 for Ubuntu 14.04 ESM.
Original advisory details:
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the
input extension protocol. A local attacker could possibly use this issue to
escalate privileges. (CVE-2020-14346)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly initialized
memory. A local attacker could possibly use this issue to obtain sensitive
information. (CVE-2020-14347)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the
XkbSelectEvents function. A local attacker could possibly use this
Ubuntu
X.Org X Server vulnerabilities
vendor_ubuntu·2020-09-02·CVSS 7.8
CVE-2020-14346 [HIGH] X.Org X Server vulnerabilities
Title: X.Org X Server vulnerabilities
Summary: Several security issues were fixed in X.Org X Server.
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the
input extension protocol. A local attacker could possibly use this issue to
escalate privileges. (CVE-2020-14346)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly initialized
memory. A local attacker could possibly use this issue to obtain sensitive
information. (CVE-2020-14347)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the
XkbSelectEvents function. A local attacker could possibly use this issue to
escalate privileges. (CVE-2020-14361)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the
XRecordRegisterClients function. A local attacker could possi
Red Hat
xorg-x11-server: Integer underflow in the X input extension protocol
vendor_redhat·2020-08-25·CVSS 7.8
CVE-2020-14346 [HIGH] CWE-191 xorg-x11-server: Integer underflow in the X input extension protocol
xorg-x11-server: Integer underflow in the X input extension protocol
A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
A flaw was found in xorg-x11-server. A integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: Xorg server does not run with root privileges in Red Hat Enterprise Linux 8, therefore this flaw has been rated as having moderate impact fo
Debian
CVE-2020-14346: xorg-server - A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X...
vendor_debian·2020·CVSS 7.8
CVE-2020-14346 [HIGH] CVE-2020-14346: xorg-server - A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X...
A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Scope: local
bookworm: resolved (fixed in 2:1.20.9-1)
bullseye: resolved (fixed in 2:1.20.9-1)
forky: resolved (fixed in 2:1.20.9-1)
sid: resolved (fixed in 2:1.20.9-1)
trixie: resolved (fixed in 2:1.20.9-1)
GHSA
GHSA-483f-26r4-2fvr: A flaw was found in xorg-x11-server before 1
ghsa_unreviewed·2022-05-24
CVE-2020-14346 [MEDIUM] CWE-190 GHSA-483f-26r4-2fvr: A flaw was found in xorg-x11-server before 1
A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
OSV
CVE-2020-14346: A flaw was found in xorg-x11-server before 1
osv·2020-09-15·CVSS 7.8
CVE-2020-14346 [HIGH] CVE-2020-14346: A flaw was found in xorg-x11-server before 1
A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
OSV
xorg-server vulnerabilities
osv·2020-09-09·CVSS 7.8
CVE-2020-14346 [HIGH] xorg-server vulnerabilities
xorg-server vulnerabilities
USN-4488-1 fixed several vulnerabilities in X.Org. This update provides
the corresponding update and also the update from USN-4490-1 for Ubuntu 14.04 ESM.
Original advisory details:
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the
input extension protocol. A local attacker could possibly use this issue to
escalate privileges. (CVE-2020-14346)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly initialized
memory. A local attacker could possibly use this issue to obtain sensitive
information. (CVE-2020-14347)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the
XkbSelectEvents function. A local attacker could possibly use this issue to
escalate privileges. (CVE-2020-14361)
Jan-Niklas Sohn discovered
OSV
xorg-server, xorg-server-hwe-16.04, xorg-server-hwe-18.04 vulnerabilities
osv·2020-09-02·CVSS 7.8
CVE-2020-14346 [HIGH] xorg-server, xorg-server-hwe-16.04, xorg-server-hwe-18.04 vulnerabilities
xorg-server, xorg-server-hwe-16.04, xorg-server-hwe-18.04 vulnerabilities
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the
input extension protocol. A local attacker could possibly use this issue to
escalate privileges. (CVE-2020-14346)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly initialized
memory. A local attacker could possibly use this issue to obtain sensitive
information. (CVE-2020-14347)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the
XkbSelectEvents function. A local attacker could possibly use this issue to
escalate privileges. (CVE-2020-14361)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the
XRecordRegisterClients function. A local attacker could possibly use this
issue to escala
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14346 xorg-x11-server: Integer underflow in the X input extension protocol [fedora-all]
bugzilla·2020-08-25·CVSS 7.8
CVE-2020-14346 [HIGH] CVE-2020-14346 xorg-x11-server: Integer underflow in the X input extension protocol [fedora-all]
CVE-2020-14346 xorg-x11-server: Integer underflow in the X input extension protocol [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2020-14346 xorg-x11-server: Integer underflow in the X input extension protocol
bugzilla·2020-07-30·CVSS 7.8
CVE-2020-14346 [HIGH] CVE-2020-14346 xorg-x11-server: Integer underflow in the X input extension protocol
CVE-2020-14346 xorg-x11-server: Integer underflow in the X input extension protocol
A flaw was found in xorg-x11-server. A integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents.
Discussion:
This bug does not yet have an embargo date set, though CVE-2020-14347 does.
---
Acknowledgments:
Name: X.org project
Upstream: Jan-Niklas Sohn (Trend Micro Zero Day Initiative)
---
Upstream commit: https://gitlab.freedesktop.org/xorg/xserver/-/commit/c940cc8b6c0a2983c1ec974f1b3f019795dd4cff
---
External References:
https://lists.x.org/archives/xorg-announce/2020-August/003058.html
---
Created xorg-x11-server tracking bugs for this issue:
Affects: fedora-all [bug 1872396]
---
Statement:
Xorg server does not run with r
https://bugzilla.redhat.com/show_bug.cgi?id=1862246https://lists.x.org/archives/xorg-announce/2020-August/003058.htmlhttps://security.gentoo.org/glsa/202012-01https://usn.ubuntu.com/4488-2/https://www.zerodayinitiative.com/advisories/ZDI-20-1417/https://bugzilla.redhat.com/show_bug.cgi?id=1862246https://lists.x.org/archives/xorg-announce/2020-August/003058.htmlhttps://security.gentoo.org/glsa/202012-01https://usn.ubuntu.com/4488-2/https://www.zerodayinitiative.com/advisories/ZDI-20-1417/
2020-09-15
Published