CVE-2018-14600
Summary
| CVE | CVE-2018-14600 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-24 19:29:00 UTC |
| Updated | 2019-08-06 17:15:00 UTC |
| Description | An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as signed instead of unsigned, resulting in an out-of-bounds write (of up to 128 bytes), leading to DoS or remote code execution. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| oss-security - X.Org security advisory: August 21, 2018 |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| [SECURITY] [DLA 1482-1] libx11 security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Bug 1102068 – VUL-0: CVE-2018-14600: libX11,xorg-x11-libX11, xorg-x11: out of boundary write in XListExtensions |
CONFIRM |
bugzilla.suse.com |
Issue Tracking, Patch, Third Party Advisory |
| X.org libX11 Bugs Let Remote Users Deny Service and Potentially Execute Arbitrary Code - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Malformed Request |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| [ANNOUNCE] libX11 1.6.6 |
MLIST |
lists.x.org |
Third Party Advisory |
| xorg/lib/libX11 - libX11 GIT Repository (mirrored from https://gitlab.freedesktop.org/xorg/lib/libx11) |
CONFIRM |
cgit.freedesktop.org |
Patch, Third Party Advisory |
| USN-3758-1: libx11 vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| USN-3758-2: libx11 vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| X.Org X11 library: Multiple vulnerabilities (GLSA 201811-01) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377269 Alibaba Cloud Linux Security Update for xorg (ALINUX2-SA-2019:0076)
- 500336 Alpine Linux Security Update for libx11
- 504099 Alpine Linux Security Update for libx11
- 671128 EulerOS Security Update for libX11 (EulerOS-SA-2019-2624)
- 710312 Gentoo Linux X.Org X11 library Multiple Vulnerabilities (GLSA 201811-01)