CVE-2020-14344
Summary
| CVE | CVE-2020-14344 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-05 14:15:00 UTC |
| Updated | 2023-11-07 03:17:00 UTC |
| Description | An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when setuid programs call XIM client functions while running with elevated privileges. No such programs are shipped with Red Hat Enterprise Linux. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 33 Update: libX11-1.6.12-1.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [security-announce] openSUSE-SU-2020:1162-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| X.Org security advisory: July 31, 2020: libX11 |
MISC |
lists.x.org |
Mailing List, Patch, Vendor Advisory |
| [SECURITY] Fedora 31 Update: libX11-1.6.12-1.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 31 Update: libX11-1.6.12-1.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| X.Org X11 library: Multiple vulnerabilities (GLSA 202008-18) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [security-announce] openSUSE-SU-2020:1198-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| [security-announce] openSUSE-SU-2020:1182-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| 1862255 – (CVE-2020-14344) CVE-2020-14344 libX11: Heap overflow in the X input method client |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| [SECURITY] Fedora 32 Update: libX11-1.6.12-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: libX11-1.6.12-1.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| USN-4487-1: libx11 vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| oss-security - Fwd: X.Org security advisory: July 31, 2020: libX11 |
MISC |
www.openwall.com |
Mailing List, Patch, Third Party Advisory |
| [SECURITY] Fedora 32 Update: libX11-1.6.12-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [security-announce] openSUSE-SU-2020:1164-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| USN-4487-2: libx11 vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159217 Oracle Enterprise Linux Security Update for userspace graphics, xorg-x11, and mesa (ELSA-2021-1804)
- 239300 Red Hat Update for userspace graphics, xorg-x11, and mesa (RHSA-2021:1804)
- 352393 Amazon Linux Security Advisory for libX11: ALAS2-2021-1661
- 377380 Alibaba Cloud Linux Security Update for userspace graphics, xorg-x11, and mesa (ALINUX3-SA-2022:0087)
- 377568 Alibaba Cloud Linux Security Update for userspace graphics, xorg-x11, and mesa (ALINUX3-SA-2022:0114)
- 500333 Alpine Linux Security Update for libx11
- 504097 Alpine Linux Security Update for libx11
- 690459 Free Berkeley Software Distribution (FreeBSD) Security Update for libx11 (6faa7feb-d3fa-11ea-9aba-0c9d925bbbc0)
- 940098 AlmaLinux Security Update for userspace (ALSA-2021:1804)
- 960449 Rocky Linux Security Update for userspace (RLSA-2021:1804)