Note:
This project will be discontinued after December 13, 2021. [more]
2020-09-15
A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Products | Ubuntu_linux, Enterprise_linux, Xorg\-Server |
Type | Integer Underflow (Wrap or Wraparound) (CWE-191) |
First patch | - None (likely due to unavailable code) |
Links |
• https://bugzilla.redhat.com/show_bug.cgi?id=1862246
• https://lists.x.org/archives/xorg-announce/2020-August/003058.html • https://security.gentoo.org/glsa/202012-01 • https://usn.ubuntu.com/4488-2/ • https://www.zerodayinitiative.com/advisories/ZDI-20-1417/ |