CVE-2020-14344
CVE-2020-14344
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 6.7EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
05 ago 2020Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when setuid programs call XIM client functions while running with elevated privileges. No such programs are shipped with Red Hat Enterprise Linux.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
The X11 Project · libX11Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00031.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14344https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4VDDSAYV7XGNRCXE7HCU23645MG74OFF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7AVXCQOSCAPKYYHFIJAZ6E2C7LJBTLXF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XY4H2SIEF2362AMNX5ZKWAELGU7LKFJB/https://lists.x.org/archives/xorg-announce/2020-July/003050.htmlhttps://security.gentoo.org/glsa/202008-18https://usn.ubuntu.com/4487-1/https://usn.ubuntu.com/4487-2/