First published: Thu Jul 30 2020(Updated: )
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNames function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
X.Org X Server | <1.20.9 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =20.04 | |
X.Org Server | ||
redhat/xorg-x11-server | <1.20.9 | 1.20.9 |
IBM Cloud Pak for Security (CP4S) | <=1.7.2.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.1.0 | |
IBM Cloud Pak for Security (CP4S) | <=1.7.0.0 | |
debian/xorg-server | 2:1.20.11-1+deb11u13 2:1.20.11-1+deb11u14 2:21.1.7-3+deb12u8 2:21.1.14-2 2:21.1.15-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14345 is a vulnerability in X.Org Server that allows local attackers to escalate privileges.
CVE-2020-14345 has a severity rating of 7.8, which is considered high.
X.Org Server installations with versions up to and including 1.20.9 are affected by CVE-2020-14345. It also affects certain versions of X.Org Server on Ubuntu and IBM Cloud Pak for Security.
To exploit CVE-2020-14345, an attacker must first be able to execute low-privileged code on the target system.
You can find more information about CVE-2020-14345 on the MITRE website (CVE-2020-14345), the X.Org Server mailing list, and the Ubuntu Security Notices (USN-4490-1).