CVE-2020-14360: Buffer Overflow
A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds access in the XkbSetMap function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
A flaw was found in X.Org Server. An Out-Of-Bounds access in XkbSetMap function may lead to a privilege escalation vulnerability. Root cause is same as CVE-2020-14345.
— Red Hat
X.Org xserver could allow a remote authenticated attacker to gain elevated privileges on the system, caused by insufficient checks on the lengths of the XkbSetMap request. By sending a specially-crafted request, an attacker could exploit this vulnerability to gain out-of-bounds memory access in the X server and escalate privileges.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-14360?
CVE-2020-14360 is a vulnerability found in the X.Org Server before version 1.20.10 that allows a remote authenticated attacker to gain elevated privileges on the system.
How does CVE-2020-14360 affect X.Org xserver?
CVE-2020-14360 affects X.Org xserver by allowing a remote authenticated attacker to gain out-of-bounds memory access in the XkbSetMap request.
How severe is CVE-2020-14360?
CVE-2020-14360 has a severity rating of high with a CVSS score of 8.8.
Which software versions are affected by CVE-2020-14360?
The X.Org Server versions before 1.20.10 are affected by CVE-2020-14360.
How can I fix CVE-2020-14360?
To fix CVE-2020-14360, it is recommended to update X.Org xserver to version 1.20.10 or higher.