CVE-2020-14347 — Improper Initialization in X Server
Severity
5.5MEDIUMNVD
OSV7.8
EPSS
0.1%
top 81.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 5
Latest updateMay 24
Description
A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages4 packages
Also affects: Debian Linux 10.0, 9.0, Ubuntu Linux 14.04, 16.04, 18.04, 20.04
Patches
🔴Vulnerability Details
5GHSA▶
GHSA-7m6m-38f5-wg3j: A flaw was found in the way xserver memory was not properly initialized↗2022-05-24
CVEList
▶
OSV
▶
📋Vendor Advisories
4💬Community
4Bugzilla▶
CVE-2020-14347 xorg-x11-server: Leak of uninitialized heap memory from the X server to clients in AllocatePixmap of dix/pixmap.c [fedora-all]↗2020-07-31
Bugzilla
▶
Bugzilla▶
CVE-2020-14347 xorg-x11-server: Leak of uninitialized heap memory from the X server to clients in AllocatePixmap of dix/pixmap.c↗2020-07-30