CVE-2020-14347Improper Initialization in X Server

Severity
5.5MEDIUMNVD
OSV7.8
EPSS
0.1%
top 81.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 5
Latest updateMay 24

Description

A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

Debianx.org/xorg-server< 2:1.20.9-1+3
Ubuntux.org/xorg-server< 2:1.18.4-0ubuntu0.9+2
NVDx.org/x_server< 1.20.9

Also affects: Debian Linux 10.0, 9.0, Ubuntu Linux 14.04, 16.04, 18.04, 20.04

Patches

🔴Vulnerability Details

5
GHSA
GHSA-7m6m-38f5-wg3j: A flaw was found in the way xserver memory was not properly initialized2022-05-24
OSV
xorg-server vulnerabilities2020-09-09
OSV
xorg-server, xorg-server-hwe-16.04, xorg-server-hwe-18.04 vulnerabilities2020-09-02
CVEList
CVE-2020-14347: A flaw was found in the way xserver memory was not properly initialized2020-08-05
OSV
CVE-2020-14347: A flaw was found in the way xserver memory was not properly initialized2020-08-05

📋Vendor Advisories

4
Ubuntu
X.Org X Server vulnerabilities2020-09-09
Ubuntu
X.Org X Server vulnerabilities2020-09-02
Red Hat
xorg-x11-server: Leak of uninitialized heap memory from the X server to clients in AllocatePixmap of dix/pixmap.c2020-07-31
Debian
CVE-2020-14347: xorg-server - A flaw was found in the way xserver memory was not properly initialized. This co...2020

💬Community

4
Bugzilla
CVE-2020-14347 xorg-x11-server: Leak of uninitialized heap memory from the X server to clients in AllocatePixmap of dix/pixmap.c [fedora-all]2020-07-31
Bugzilla
CVE-2020-14345 xorg-x11-server: Out-of-bounds access in XkbSetNames function2020-07-30
Bugzilla
CVE-2020-14346 xorg-x11-server: Integer underflow in the X input extension protocol2020-07-30
Bugzilla
CVE-2020-14347 xorg-x11-server: Leak of uninitialized heap memory from the X server to clients in AllocatePixmap of dix/pixmap.c2020-07-30
CVE-2020-14347 — Improper Initialization in X Server | cvebase