Out-of-Bounds
Affecting xorg-server package, versions <2:1.20.4-1+deb10u1
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to Out-of-Bounds. A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNames function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Remediation
Upgrade xorg-server
to version or higher.
References
CVSS Score
7.8
high severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredLow
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2020-14345
- CWE
- CWE-119
- Snyk ID
- SNYK-DEBIAN10-XORGSERVER-608566
- Disclosed
- 15 Sep, 2020
- Published
- 26 Aug, 2020