CVE-2020-14344
Last modified
CVE-2020-14344 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when setuid programs call XIM client functions while running with elevated privileges. EPSS estimates a 0.48% chance of exploitation in the next 30 days.
Description
An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when setuid programs call XIM client functions while running with elevated privileges. No such programs are shipped with Red Hat Enterprise Linux.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| X.Org | Libx11 | < 1.6.10 |
| Fedoraproject | Fedora | 31 |
| Fedoraproject | Fedora | 32 |
| Fedoraproject | Fedora | 33 |
| Canonical | Ubuntu Linux | 12.04 |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 20.04 |
| Opensuse | Leap | 15.1 |
| Opensuse | Leap | 15.2 |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00014.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00015.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00024.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00031.htmlMailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14344Issue Tracking, Patch, Third Party Advisory
- https://lists.x.org/archives/xorg-announce/2020-July/003050.htmlMailing List, Patch, Vendor Advisory
- https://security.gentoo.org/glsa/202008-18Third Party Advisory
- https://usn.ubuntu.com/4487-1/Third Party Advisory
- https://usn.ubuntu.com/4487-2/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2020/07/31/1Mailing List, Patch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00014.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00015.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00024.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00031.htmlMailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14344Issue Tracking, Patch, Third Party Advisory
- https://lists.x.org/archives/xorg-announce/2020-July/003050.htmlMailing List, Patch, Vendor Advisory
- https://security.gentoo.org/glsa/202008-18Third Party Advisory
- https://usn.ubuntu.com/4487-1/Third Party Advisory
- https://usn.ubuntu.com/4487-2/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2020/07/31/1Mailing List, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-14344?
How severe is CVE-2020-14344?
How do I fix CVE-2020-14344?
Are you affected by CVE-2020-14344?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
