Integer Overflow or Wraparound
Affecting xorg-server package, versions <2:1.19.2-1+deb9u6
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to Integer Overflow or Wraparound. A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Remediation
Upgrade xorg-server
to version or higher.
References
CVSS Score
7.8
high severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredLow
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2020-14346
- CWE
- CWE-190
- Snyk ID
- SNYK-DEBIAN9-XORGSERVER-608570
- Disclosed
- 15 Sep, 2020
- Published
- 26 Aug, 2020