CVE-2018-14665
25.10.2018, 20:29
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| x.org | x_server | 𝑥 < 1.20.3 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_aus | 7.6 |
| redhat | enterprise_linux_server_eus | 7.6 |
| redhat | enterprise_linux_server_tus | 7.6 |
| redhat | enterprise_linux_workstation | 7.0 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 18.10 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| xorg |
| ||||||||
| xorg-hwe-16.04 |
| ||||||||
| xorg-server |
| ||||||||
| xorg-server-hwe-16.04 |
| ||||||||
| xorg-server-lts-utopic |
| ||||||||
| xorg-server-lts-vivid |
| ||||||||
| xorg-server-lts-wily |
| ||||||||
| xorg-server-lts-xenial |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| xorg-x11-server |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| xorg-x11-server-Xvfb |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| xorg-x11-server-extra |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| xorg-x11-server-Xdmx |
| ||
| xorg-x11-server-Xephyr |
| ||
| xorg-x11-server-Xnest |
| ||
| xorg-x11-server-Xorg |
| ||
| xorg-x11-server-Xvfb |
| ||
| xorg-x11-server-Xwayland |
| ||
| xorg-x11-server-common |
| ||
| xorg-x11-server-devel |
| ||
| xorg-x11-server-source |
|
References