CVE-2020-14363
CVE-2020-14363
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 7.8EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
11 sep 2020Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application compiled with libX11 to crash, or in some cases, result in arbitrary code execution. The highest threat from this flaw is to confidentiality, integrity as well as system availability.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
The X11 Project · libX11¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14363https://github.com/Ruia-ruia/Exploits/blob/master/DFX11details.txthttps://github.com/Ruia-ruia/Exploits/blob/master/x11doublefree.shhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7AVXCQOSCAPKYYHFIJAZ6E2C7LJBTLXF/https://lists.x.org/archives/xorg-announce/2020-August/003056.htmlhttps://usn.ubuntu.com/4487-2/