4.6
CVSSv2

CVE-2020-25712

Published: 15/12/2020 Updated: 16/12/2020
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A flaw was found in xorg-x11-server prior to 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

x.org x server

redhat enterprise linux 8.0

Vendor Advisories

Synopsis Important: xorg-x11-server security update Type/Severity Security Advisory: Important Topic An update for xorg-x11-server is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (C ...
Debian Bug report logs - #976216 xorg-server: CVE-2020-25712 CVE-2020-14360 Package: src:xorg-server; Maintainer for src:xorg-server is Debian X Strike Force <debian-x@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 1 Dec 2020 17:03:02 UTC Severity: grave Tags: security, upstream ...
Debian Bug report logs - #980061 caribou: Segfault as regression of xorg CVE-2020-25712 fix that cause security issue for cinnamon Package: src:caribou; Maintainer for src:caribou is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Reported by: fantonifabio@tiscaliit Date: Wed, 13 Jan 2021 18:45:02 ...
Jan-Niklas Sohn discovered that the XKB extension of the Xorg X server performed incomplete input validation, which could result in privilege escalation For the stable distribution (buster), these problems have been fixed in version 2:1204-1+deb10u2 We recommend that you upgrade your xorg-server packages For the detailed security status of xor ...
A flaw was found in the way the Xserver memory was not properly initialized This issue leak parts of server memory to the X client In cases where the Xorg server runs with elevated privileges, this flaw results in a possible ASLR bypass (CVE-2020-14347) A flaw was found in the XOrg Server An out-of-bounds access in the XkbSetMap function may l ...
A security issue was discovered in xorg-server before 12010 Insufficient checks on input of the XkbSetDeviceInfo request can lead to a buffer overflow on the head in the X server This issue can lead to privilege escalation for authorized clients on systems where the X server is running privileged ...