CVE-2020-14345
Summary
| CVE | CVE-2020-14345 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-15 14:15:00 UTC |
| Updated | 2022-10-07 14:07:00 UTC |
| Description | A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNames function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| USN-4488-2: X.Org X Server vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| X.Org server security advisory: August 25, 2020 |
MISC |
lists.x.org |
Vendor Advisory |
| oss-security - Re: [vs] Cinnamon lock screen bypass in multiple distributions |
MLIST |
www.openwall.com |
|
| X.Org X Server: Multiple vulnerabilities (GLSA 202012-01) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| USN-4490-1: X.Org X Server vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| 1862241 – (CVE-2020-14345) CVE-2020-14345 xorg-x11-server: Out-Of-Bounds access in XkbSetNames function |
MISC |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| ZDI-20-1416 | Zero Day Initiative |
MISC |
www.zerodayinitiative.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159217 Oracle Enterprise Linux Security Update for userspace graphics, xorg-x11, and mesa (ELSA-2021-1804)
- 239300 Red Hat Update for userspace graphics, xorg-x11, and mesa (RHSA-2021:1804)
- 352294 Amazon Linux Security Update for xorg-x11-server: AL2012-2021-336
- 377209 Alibaba Cloud Linux Security Update for xorg-x11-server (ALINUX2-SA-2020:0176)
- 377380 Alibaba Cloud Linux Security Update for userspace graphics, xorg-x11, and mesa (ALINUX3-SA-2022:0087)
- 377568 Alibaba Cloud Linux Security Update for userspace graphics, xorg-x11, and mesa (ALINUX3-SA-2022:0114)
- 378230 Virtuozzo Linux Security Update for xorg-x11-server-Xnest (VZLSA-2020:4953)
- 500826 Alpine Linux Security Update for xorg-server
- 690732 Free Berkeley Software Distribution (FreeBSD) Security Update for xorg-server (ffa15b3b-e6f6-11ea-8cbf-54e1ad3d6335)
- 730227 McAfee Web Gateway Multiple Vulnerabilities (WP-3426, WP-3427, WP-3307, WP-3444, WP-3452, WP-3475)
- 940098 AlmaLinux Security Update for userspace (ALSA-2021:1804)
- 960449 Rocky Linux Security Update for userspace (RLSA-2021:1804)