CVE-2020-14347
published 2020-08-05CVE-2020-14347: A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server…
PriorityP427medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.39%
31.4th percentile
A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | xorg-server | < xorg-server 2:1.20.9-1 (bookworm) | xorg-server 2:1.20.9-1 (bookworm) |
| the_xorg_project | xorg-x11-server | — | — |
| x.org | x_server | < 1.20.9 | 1.20.9 |
| x.org | xorg-server | >= 0 < 2:1.20.9-1 | 2:1.20.9-1 |
| x.org | xorg-server | >= 0 < 2:1.20.9-1 | 2:1.20.9-1 |
| x.org | xorg-server | >= 0 < 2:1.20.9-1 | 2:1.20.9-1 |
| x.org | xorg-server | >= 0 < 2:1.20.9-1 | 2:1.20.9-1 |
| x.org | xorg-server | >= 0 < 2:1.18.4-0ubuntu0.9 | 2:1.18.4-0ubuntu0.9 |
| x.org | xorg-server | >= 0 < 2:1.19.6-1ubuntu4.5 | 2:1.19.6-1ubuntu4.5 |
| x.org | xorg-server | >= 0 < 2:1.20.8-2ubuntu2.3 | 2:1.20.8-2ubuntu2.3 |
| x.org | xorg-server | >= 0 < 2:1.15.1-0ubuntu2.11+esm2 | 2:1.15.1-0ubuntu2.11+esm2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
X.Org X Server vulnerabilities
vendor_ubuntu·2020-09-09·CVSS 7.8
CVE-2020-14345 [HIGH] X.Org X Server vulnerabilities
Title: X.Org X Server vulnerabilities
Summary: Several security issues were fixed in X.Org X Server.
USN-4488-1 fixed several vulnerabilities in X.Org. This update provides
the corresponding update and also the update from USN-4490-1 for Ubuntu 14.04 ESM.
Original advisory details:
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the
input extension protocol. A local attacker could possibly use this issue to
escalate privileges. (CVE-2020-14346)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly initialized
memory. A local attacker could possibly use this issue to obtain sensitive
information. (CVE-2020-14347)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the
XkbSelectEvents function. A local attacker could possibly use this
Ubuntu
X.Org X Server vulnerabilities
vendor_ubuntu·2020-09-02·CVSS 7.8
CVE-2020-14346 [HIGH] X.Org X Server vulnerabilities
Title: X.Org X Server vulnerabilities
Summary: Several security issues were fixed in X.Org X Server.
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the
input extension protocol. A local attacker could possibly use this issue to
escalate privileges. (CVE-2020-14346)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly initialized
memory. A local attacker could possibly use this issue to obtain sensitive
information. (CVE-2020-14347)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the
XkbSelectEvents function. A local attacker could possibly use this issue to
escalate privileges. (CVE-2020-14361)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the
XRecordRegisterClients function. A local attacker could possi
Red Hat
xorg-x11-server: Leak of uninitialized heap memory from the X server to clients in AllocatePixmap of dix/pixmap.c
vendor_redhat·2020-07-31·CVSS 5.5
CVE-2020-14347 [MEDIUM] CWE-665 xorg-x11-server: Leak of uninitialized heap memory from the X server to clients in AllocatePixmap of dix/pixmap.c
xorg-x11-server: Leak of uninitialized heap memory from the X server to clients in AllocatePixmap of dix/pixmap.c
A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.
A flaw was found in the way the Xserver memory was not properly initialized. This issue leak parts of server memory to the X client. In cases where the Xorg server runs with elevated privileges, this flaw results in a possible ASLR bypass.
Package: xorg-x11-server (Red Hat Enterprise Linux 5) - Out of support scope
Package: xorg-x11-server (Red Hat Enterprise Linux 6) - Out of support scope
Package:
Debian
CVE-2020-14347: xorg-server - A flaw was found in the way xserver memory was not properly initialized. This co...
vendor_debian·2020·CVSS 5.5
CVE-2020-14347 [MEDIUM] CVE-2020-14347: xorg-server - A flaw was found in the way xserver memory was not properly initialized. This co...
A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.
Scope: local
bookworm: resolved (fixed in 2:1.20.9-1)
bullseye: resolved (fixed in 2:1.20.9-1)
forky: resolved (fixed in 2:1.20.9-1)
sid: resolved (fixed in 2:1.20.9-1)
trixie: resolved (fixed in 2:1.20.9-1)
GHSA
GHSA-7m6m-38f5-wg3j: A flaw was found in the way xserver memory was not properly initialized
ghsa_unreviewed·2022-05-24
CVE-2020-14347 [LOW] CWE-665 GHSA-7m6m-38f5-wg3j: A flaw was found in the way xserver memory was not properly initialized
A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.
OSV
xorg-server vulnerabilities
osv·2020-09-09·CVSS 7.8
CVE-2020-14346 [HIGH] xorg-server vulnerabilities
xorg-server vulnerabilities
USN-4488-1 fixed several vulnerabilities in X.Org. This update provides
the corresponding update and also the update from USN-4490-1 for Ubuntu 14.04 ESM.
Original advisory details:
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the
input extension protocol. A local attacker could possibly use this issue to
escalate privileges. (CVE-2020-14346)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly initialized
memory. A local attacker could possibly use this issue to obtain sensitive
information. (CVE-2020-14347)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the
XkbSelectEvents function. A local attacker could possibly use this issue to
escalate privileges. (CVE-2020-14361)
Jan-Niklas Sohn discovered
OSV
xorg-server, xorg-server-hwe-16.04, xorg-server-hwe-18.04 vulnerabilities
osv·2020-09-02·CVSS 7.8
CVE-2020-14346 [HIGH] xorg-server, xorg-server-hwe-16.04, xorg-server-hwe-18.04 vulnerabilities
xorg-server, xorg-server-hwe-16.04, xorg-server-hwe-18.04 vulnerabilities
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the
input extension protocol. A local attacker could possibly use this issue to
escalate privileges. (CVE-2020-14346)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly initialized
memory. A local attacker could possibly use this issue to obtain sensitive
information. (CVE-2020-14347)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the
XkbSelectEvents function. A local attacker could possibly use this issue to
escalate privileges. (CVE-2020-14361)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the
XRecordRegisterClients function. A local attacker could possibly use this
issue to escala
OSV
CVE-2020-14347: A flaw was found in the way xserver memory was not properly initialized
osv·2020-08-05·CVSS 5.5
CVE-2020-14347 [MEDIUM] CVE-2020-14347: A flaw was found in the way xserver memory was not properly initialized
A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14347 xorg-x11-server: Leak of uninitialized heap memory from the X server to clients in AllocatePixmap of dix/pixmap.c [fedora-all]
bugzilla·2020-07-31·CVSS 5.5
CVE-2020-14347 [MEDIUM] CVE-2020-14347 xorg-x11-server: Leak of uninitialized heap memory from the X server to clients in AllocatePixmap of dix/pixmap.c [fedora-all]
CVE-2020-14347 xorg-x11-server: Leak of uninitialized heap memory from the X server to clients in AllocatePixmap of dix/pixmap.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commi
Bugzilla
CVE-2020-14345 xorg-x11-server: Out-of-bounds access in XkbSetNames function
bugzilla·2020-07-30·CVSS 7.8
CVE-2020-14345 [HIGH] CVE-2020-14345 xorg-x11-server: Out-of-bounds access in XkbSetNames function
CVE-2020-14345 xorg-x11-server: Out-of-bounds access in XkbSetNames function
A flaw was found in X.Org Server. An Out-Of-Bounds access in XkbSetNames function may lead to a privilege escalation vulnerability.
Discussion:
This bug does not yet have an embargo date set, though CVE-2020-14347 does.
---
Acknowledgments:
Name: X.org project
Upstream: Jan-Niklas Sohn (Trend Micro Zero Day Initiative)
---
External References:
https://lists.x.org/archives/xorg-announce/2020-August/003058.html
---
Created xorg-x11-server tracking bugs for this issue:
Affects: fedora-all [bug 1872386]
---
Upstream commit:
https://gitlab.freedesktop.org/xorg/xserver/-/commit/f7cd1276bbd4fe3a9700096dec33b52b8440788d
---
Statement:
Xorg server does not run with root privileges in Red Hat Enterprise Li
Bugzilla
CVE-2020-14346 xorg-x11-server: Integer underflow in the X input extension protocol
bugzilla·2020-07-30·CVSS 7.8
CVE-2020-14346 [HIGH] CVE-2020-14346 xorg-x11-server: Integer underflow in the X input extension protocol
CVE-2020-14346 xorg-x11-server: Integer underflow in the X input extension protocol
A flaw was found in xorg-x11-server. A integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents.
Discussion:
This bug does not yet have an embargo date set, though CVE-2020-14347 does.
---
Acknowledgments:
Name: X.org project
Upstream: Jan-Niklas Sohn (Trend Micro Zero Day Initiative)
---
Upstream commit: https://gitlab.freedesktop.org/xorg/xserver/-/commit/c940cc8b6c0a2983c1ec974f1b3f019795dd4cff
---
External References:
https://lists.x.org/archives/xorg-announce/2020-August/003058.html
---
Created xorg-x11-server tracking bugs for this issue:
Affects: fedora-all [bug 1872396]
---
Statement:
Xorg server does not run with r
Bugzilla
CVE-2020-14347 xorg-x11-server: Leak of uninitialized heap memory from the X server to clients in AllocatePixmap of dix/pixmap.c
bugzilla·2020-07-30·CVSS 5.5
CVE-2020-14347 [MEDIUM] CVE-2020-14347 xorg-x11-server: Leak of uninitialized heap memory from the X server to clients in AllocatePixmap of dix/pixmap.c
CVE-2020-14347 xorg-x11-server: Leak of uninitialized heap memory from the X server to clients in AllocatePixmap of dix/pixmap.c
Allocation for pixmap data in AllocatePixmap() does not initialize the memory in xserver, it leads to leak uninitialize heap memory to clients. When the X server runs with elevated privileges, this can lead to privilege elevation in the client.
Discussion:
Acknowledgments:
Name: X.org project
Upstream: Jan-Niklas Sohn (Trend Micro Zero Day Initiative)
---
Public via:
https://www.openwall.com/lists/oss-security/2020/07/31/2
---
Created xorg-x11-server tracking bugs for this issue:
Affects: fedora-all [bug 1862517]
---
External References:
https://lists.x.org/archives/xorg-announce/2020-July/003051.html
---
This issue has been addressed in the follow
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00066.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00075.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14347https://lists.debian.org/debian-lts-announce/2020/08/msg00057.htmlhttps://lists.x.org/archives/xorg-announce/2020-July/003051.htmlhttps://security.gentoo.org/glsa/202012-01https://usn.ubuntu.com/4488-1/https://usn.ubuntu.com/4488-2/https://www.debian.org/security/2020/dsa-4758https://www.openwall.com/lists/oss-security/2020/07/31/2http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00066.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00075.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14347https://lists.debian.org/debian-lts-announce/2020/08/msg00057.htmlhttps://lists.x.org/archives/xorg-announce/2020-July/003051.htmlhttps://security.gentoo.org/glsa/202012-01https://usn.ubuntu.com/4488-1/https://usn.ubuntu.com/4488-2/https://www.debian.org/security/2020/dsa-4758https://www.openwall.com/lists/oss-security/2020/07/31/2
2020-08-05
Published