CVE-2018-14665: High severity X.Org xorg-server vulnerability
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.
Other sources
The X.org X11 server has a vulnerability that allows local users to escalate to full root privileges. The /usr/bin/Xorg setuid binary shipped in the xorg-x11-server-Xorg package allows for arbitrary file creation with certain parameters, allowing attackers with low privilege access to overwrite system files and subsequently execute arbitrary code.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-14665?
CVE-2018-14665 is a vulnerability in xorg-x11-server before version 1.20.3 that allows unprivileged users to escalate their privileges and run arbitrary code under root.
How severe is CVE-2018-14665?
CVE-2018-14665 is considered a high severity vulnerability with a CVSS score of 6.6.
Which software versions are affected by CVE-2018-14665?
xorg-x11-server versions up to but excluding 1.20.3 are affected by CVE-2018-14665.
How can I fix CVE-2018-14665?
To fix CVE-2018-14665, update xorg-x11-server to version 1.20.3 or later.
Where can I find more information about CVE-2018-14665?
You can find more information about CVE-2018-14665 at the following references: [Packetstorm Security 1](http://packetstormsecurity.com/files/154942/Xorg-X11-Server-SUID-modulepath-Privilege-Escalation.html), [Packetstorm Security 2](http://packetstormsecurity.com/files/155276/Xorg-X11-Server-Local-Privilege-Escalation.html), [SecurityFocus](http://www.securityfocus.com/bid/105741).