Unrated severityNVD Advisory· Published Sep 11, 2020· Updated Aug 4, 2024
CVE-2020-14363
CVE-2020-14363
Description
An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application compiled with libX11 to crash, or in some cases, result in arbitrary code execution. The highest threat from this flaw is to confidentiality, integrity as well as system availability.
Affected products
42- osv-coords41 versionspkg:rpm/almalinux/libglvndpkg:rpm/almalinux/libglvnd-core-develpkg:rpm/almalinux/libglvnd-develpkg:rpm/almalinux/libglvnd-eglpkg:rpm/almalinux/libglvnd-glespkg:rpm/almalinux/libglvnd-glxpkg:rpm/almalinux/libglvnd-openglpkg:rpm/almalinux/libinput-develpkg:rpm/almalinux/libwacom-develpkg:rpm/almalinux/mesa-libgbm-develpkg:rpm/almalinux/mesa-libOSMesa-develpkg:rpm/almalinux/xorg-x11-driverspkg:rpm/almalinux/xorg-x11-server-develpkg:rpm/almalinux/xorg-x11-server-sourcepkg:rpm/opensuse/libX11&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/libX11&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/libX11&distro=openSUSE%20Tumbleweedpkg:rpm/suse/libX11&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/libX11&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/libX11&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/libX11&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/libX11&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/libX11&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/libX11&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/libX11&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/libX11&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/libX11&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/libX11&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/libX11&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/libX11&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/libX11&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/libX11&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/libX11&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/libX11&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/libX11&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/libX11&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/libX11&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/libX11&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/libX11&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/libX11&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/libX11&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209
< 1:1.3.2-1.el8+ 40 more
- (no CPE)range: < 1:1.3.2-1.el8
- (no CPE)range: < 1:1.3.2-1.el8
- (no CPE)range: < 1:1.3.2-1.el8
- (no CPE)range: < 1:1.3.2-1.el8
- (no CPE)range: < 1:1.3.2-1.el8
- (no CPE)range: < 1:1.3.2-1.el8
- (no CPE)range: < 1:1.3.2-1.el8
- (no CPE)range: < 1.16.3-1.el8
- (no CPE)range: < 1.6-2.el8
- (no CPE)range: < 20.3.3-2.el8
- (no CPE)range: < 20.3.3-2.el8
- (no CPE)range: < 7.7-30.el8
- (no CPE)range: < 1.20.10-1.el8
- (no CPE)range: < 1.20.10-1.el8
- (no CPE)range: < 1.6.5-lp151.4.9.1
- (no CPE)range: < 1.6.5-lp152.5.9.1
- (no CPE)range: < 1.7.2-1.2
- (no CPE)range: < 1.6.2-12.15.1
- (no CPE)range: < 1.6.2-12.15.1
- (no CPE)range: < 1.6.5-3.12.1
- (no CPE)range: < 1.6.5-3.12.1
- (no CPE)range: < 1.6.5-3.12.1
- (no CPE)range: < 1.6.5-3.12.1
- (no CPE)range: < 1.6.2-12.15.1
- (no CPE)range: < 1.6.2-12.15.1
- (no CPE)range: < 1.6.2-12.15.1
- (no CPE)range: < 1.6.2-12.15.1
- (no CPE)range: < 1.6.2-12.15.1
- (no CPE)range: < 1.6.2-12.15.1
- (no CPE)range: < 1.6.5-3.12.1
- (no CPE)range: < 1.6.2-12.15.1
- (no CPE)range: < 1.6.2-12.15.1
- (no CPE)range: < 1.6.2-12.15.1
- (no CPE)range: < 1.6.2-12.15.1
- (no CPE)range: < 1.6.5-3.12.1
- (no CPE)range: < 1.6.2-12.15.1
- (no CPE)range: < 1.6.2-12.15.1
- (no CPE)range: < 1.6.2-12.15.1
- (no CPE)range: < 1.6.2-12.15.1
- (no CPE)range: < 1.6.2-12.15.1
- (no CPE)range: < 1.6.2-12.15.1
- The X11 Project/libX11v5Range: 1.6.12
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7AVXCQOSCAPKYYHFIJAZ6E2C7LJBTLXF/mitrevendor-advisoryx_refsource_FEDORA
- usn.ubuntu.com/4487-2/mitrevendor-advisoryx_refsource_UBUNTU
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_CONFIRM
- github.com/Ruia-ruia/Exploits/blob/master/DFX11details.txtmitrex_refsource_MISC
- github.com/Ruia-ruia/Exploits/blob/master/x11doublefree.shmitrex_refsource_MISC
- lists.x.org/archives/xorg-announce/2020-August/003056.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.