Out-Of-Bounds Access Vulnerability in X.Org Server Affecting Data Confidentiality
CVE-2020-14345

7.8HIGH

Key Information:

Vendor

X.org

Vendor
CVE Published:
15 September 2020

What is CVE-2020-14345?

A vulnerability exists in X.Org Server versions prior to 1.20.9, specifically related to an Out-Of-Bounds access in the XkbSetNames function. This flaw could potentially allow attackers to escalate their privileges, which poses significant risks to data confidentiality, integrity, and overall system availability. The exploitation of this vulnerability highlights the need for timely updates and security patches to protect systems that rely on X.Org Server. Organizations are advised to monitor and apply the relevant updates to mitigate the associated risks.

Affected Version(s)

xorg-x11-server before xorg-x11-server 1.20.9

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.