CVE-2018-14598
Summary
| CVE | CVE-2018-14598 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-24 19:29:00 UTC |
| Updated | 2023-11-07 02:52:00 UTC |
| Description | An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in which the first string overflows, causing a variable to be set to NULL that will be freed later on, leading to DoS (segmentation fault). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| oss-security - X.Org security advisory: August 21, 2018 |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| [SECURITY] [DLA 1482-1] libx11 security update |
MLIST |
lists.debian.org |
Third Party Advisory |
| [SECURITY] Fedora 28 Update: libX11-1.6.7-1.fc28 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| xorg/lib/libX11 - libX11 GIT Repository (mirrored from https://gitlab.freedesktop.org/xorg/lib/libx11) |
CONFIRM |
cgit.freedesktop.org |
Patch, Third Party Advisory |
| Bug 1102073 – VUL-0: CVE-2018-14598: libX11,xorg-x11-libX11, xorg-x11: crash on invalid reply in XListExtensions |
CONFIRM |
bugzilla.suse.com |
Issue Tracking, Patch, Third Party Advisory |
| X.org libX11 Bugs Let Remote Users Deny Service and Potentially Execute Arbitrary Code - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| [SECURITY] Fedora 28 Update: libX11-1.6.7-1.fc28 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Release Notes, Third Party Advisory |
| Malformed Request |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| [ANNOUNCE] libX11 1.6.6 |
MLIST |
lists.x.org |
Third Party Advisory |
| USN-3758-1: libx11 vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| USN-3758-2: libx11 vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| X.Org X11 library: Multiple vulnerabilities (GLSA 201811-01) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377269 Alibaba Cloud Linux Security Update for xorg (ALINUX2-SA-2019:0076)
- 500336 Alpine Linux Security Update for libx11
- 504099 Alpine Linux Security Update for libx11
- 671128 EulerOS Security Update for libX11 (EulerOS-SA-2019-2624)
- 710312 Gentoo Linux X.Org X11 library Multiple Vulnerabilities (GLSA 201811-01)