CVE-2020-14347
05.08.2020, 14:15
A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| x.org | x_server | 𝑥 < 1.20.9 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 20.04 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| xorg |
| ||||||||
| xorg-hwe-16.04 |
| ||||||||
| xorg-server |
| ||||||||
| xorg-server-hwe-16.04 |
| ||||||||
| xorg-server-hwe-18.04 |
| ||||||||
| xorg-server-lts-utopic |
| ||||||||
| xorg-server-lts-vivid |
| ||||||||
| xorg-server-lts-wily |
| ||||||||
| xorg-server-lts-xenial |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| xorg-x11-server |
| ||||||||||||||||||||||||||||||||||||||||||||||||||
| xorg-x11-server-Xvfb |
| ||||||||||||||||||||||||||||||||||||||||||||||||||
| xorg-x11-server-extra |
| ||||||||||||||||||||||||||||||||||||||||||||||||||
| xorg-x11-server-sdk |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| egl-wayland |
| ||||
| libX11 |
| ||||
| libX11-common |
| ||||
| libX11-devel |
| ||||
| libX11-xcb |
| ||||
| libdrm |
| ||||
| libdrm-devel |
| ||||
| libglvnd |
| ||||
| libglvnd-core-devel |
| ||||
| libglvnd-devel |
| ||||
| libglvnd-egl |
| ||||
| libglvnd-gles |
| ||||
| libglvnd-glx |
| ||||
| libglvnd-opengl |
| ||||
| libinput |
| ||||
| libinput-devel |
| ||||
| libinput-utils |
| ||||
| libwacom |
| ||||
| libwacom-data |
| ||||
| libwacom-devel |
| ||||
| mesa-dri-drivers |
| ||||
| mesa-filesystem |
| ||||
| mesa-libEGL |
| ||||
| mesa-libEGL-devel |
| ||||
| mesa-libGL |
| ||||
| mesa-libGL-devel |
| ||||
| mesa-libOSMesa |
| ||||
| mesa-libOSMesa-devel |
| ||||
| mesa-libgbm |
| ||||
| mesa-libgbm-devel |
| ||||
| mesa-libglapi |
| ||||
| mesa-libxatracker |
| ||||
| mesa-vdpau-drivers |
| ||||
| mesa-vulkan-devel |
| ||||
| mesa-vulkan-drivers |
| ||||
| xorg-x11-drivers |
| ||||
| xorg-x11-server-Xdmx |
| ||||
| xorg-x11-server-Xephyr |
| ||||
| xorg-x11-server-Xnest |
| ||||
| xorg-x11-server-Xorg |
| ||||
| xorg-x11-server-Xvfb |
| ||||
| xorg-x11-server-Xwayland |
| ||||
| xorg-x11-server-common |
| ||||
| xorg-x11-server-devel |
| ||||
| xorg-x11-server-source |
|
Common Weakness Enumeration
References