Integer Underflow Vulnerability in xorg-x11-server Affects Multiple Linux Distributions
CVE-2020-14346

7.8HIGH

Key Information:

Vendor

X.org

Vendor
CVE Published:
15 September 2020

What is CVE-2020-14346?

A flaw exists in the xorg-x11-server prior to version 1.20.9, where an integer underflow in the X input extension protocol decoding can lead to arbitrary memory access. This vulnerability poses serious risks to data confidentiality and integrity, and can compromise system availability, making it essential for users and administrators to address this issue swiftly to maintain the security of their systems.

Affected Version(s)

xorg-x11-server before xorg-x11-server 1.20.9

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.