Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2020-14362: xorg-x11-server: XRecordRegisterClients Integer Underflow Privilege Escalation Vulnerability (ZDI 11574) | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Alexandros Toptsoglou <atoptsoglou> |
Component: | Incidents | Assignee: | Security Team bot <security-team> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Major | ||
Priority: | P3 - Medium | CC: | sndirsch, tiwai, wolfgang.frisch |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/264777/ | ||
Whiteboard: | CVSSv3.1:SUSE:CVE-2020-14362:7.8:(AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) | ||
Found By: | --- | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Attachments: | ZDI-CAN-11574.zip |
Description
Alexandros Toptsoglou
2020-08-05 12:26:09 UTC
Date: Tue, 25 Aug 2020 17:24:05 +0200 From: Matthieu Herrb <matthieu@herrb.eu> To: xorg-announce@lists.x.org Subject: X.Org server security advisory: August 25, 2020 Multiple input validation failures in X server extensions ========================================================= All theses issuses can lead to local privileges elevation on systems where the X server is running privileged. * CVE-2020-14345 / ZDI CAN 11428 XkbSetNames Out-Of-Bounds Access The handler for the XkbSetNames request does not validate the request length before accessing its contents. * CVE-2020-14346 / ZDI CAN 11429 XIChangeHierarchy Integer Underflow An integer underflow exists in the handler for the XIChangeHierarchy request. * CVE-2020-14361 / ZDI CAN 11573 XkbSelectEvents Integer Underflow An integer underflow exist in the handler for the XkbSelectEvents request. * CVE-2020-1436 / ZDI CAN 11574 XRecordRegisterClients Integer Underflow An integer underflow exist in the handler for the CreateRegister request of the X record extension. Patches ------- Patches for this issues have been commited to the xorg server git repository. xorg-server 1.20.9 will be released shortly and will include these patches. https://gitlab.freedesktop.org/xorg/xserver.git commit 11f22a3bf694d7061d552c99898d843bcdaf0cf1 Correct bounds checking in XkbSetNames() CVE-2020-14345 / ZDI 11428 commit 1e3392b07923987c6c9d09cf75b24f397b59bd5e Fix XIChangeHierarchy() integer underflow CVE-2020-14346 / ZDI-CAN-11429 commit 90304b3c2018a6b8f4a79de86364d2af15cb9ad8 Fix XkbSelectEvents() integer underflow CVE-2020-14361 ZDI-CAN 11573 commit 24acad216aa0fc2ac451c67b2b86db057a032050 Fix XRecordRegisterClients() Integer underflow CVE-2020-14362 ZDI-CAN-11574 Thanks ====== These vulnerabilities have beend discovered by Jan-Niklas Sohn working with Trend Micro Zero Day Initiative. -- Matthieu Herrb This is an autogenerated message for OBS integration: This bug (1174913) was mentioned in https://build.opensuse.org/request/show/829591 Factory / xorg-x11-server Packages are submitted (factory/TW, sle15-sp2, sle15-sp1, sle15, sle12-sp5, sle12-sp4, sle12-sp2, sle11-sp3, sle11-sp1). Reassigning back to security team. SUSE-SU-2020:2399-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1174910,1174913 CVE References: CVE-2020-14361,CVE-2020-14362 JIRA References: Sources used: SUSE OpenStack Cloud Crowbar 9 (src): xorg-x11-server-1.19.6-4.11.1 SUSE OpenStack Cloud 9 (src): xorg-x11-server-1.19.6-4.11.1 SUSE Linux Enterprise Server for SAP 12-SP4 (src): xorg-x11-server-1.19.6-4.11.1 SUSE Linux Enterprise Server 12-SP4-LTSS (src): xorg-x11-server-1.19.6-4.11.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2020:2398-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1174910,1174913 CVE References: CVE-2020-14361,CVE-2020-14362 JIRA References: Sources used: SUSE Linux Enterprise Server for SAP 15 (src): xorg-x11-server-1.19.6-8.19.1 SUSE Linux Enterprise Server 15-LTSS (src): xorg-x11-server-1.19.6-8.19.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): xorg-x11-server-1.19.6-8.19.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): xorg-x11-server-1.19.6-8.19.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2020:2401-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1174910,1174913 CVE References: CVE-2020-14361,CVE-2020-14362 JIRA References: Sources used: SUSE OpenStack Cloud Crowbar 8 (src): xorg-x11-server-7.6_1.18.3-76.29.1 SUSE OpenStack Cloud 8 (src): xorg-x11-server-7.6_1.18.3-76.29.1 SUSE OpenStack Cloud 7 (src): xorg-x11-server-7.6_1.18.3-76.29.1 SUSE Linux Enterprise Server for SAP 12-SP3 (src): xorg-x11-server-7.6_1.18.3-76.29.1 SUSE Linux Enterprise Server for SAP 12-SP2 (src): xorg-x11-server-7.6_1.18.3-76.29.1 SUSE Linux Enterprise Server 12-SP3-LTSS (src): xorg-x11-server-7.6_1.18.3-76.29.1 SUSE Linux Enterprise Server 12-SP3-BCL (src): xorg-x11-server-7.6_1.18.3-76.29.1 SUSE Linux Enterprise Server 12-SP2-LTSS (src): xorg-x11-server-7.6_1.18.3-76.29.1 SUSE Linux Enterprise Server 12-SP2-BCL (src): xorg-x11-server-7.6_1.18.3-76.29.1 SUSE Enterprise Storage 5 (src): xorg-x11-server-7.6_1.18.3-76.29.1 HPE Helion Openstack 8 (src): xorg-x11-server-7.6_1.18.3-76.29.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2020:14475-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1174910,1174913 CVE References: CVE-2020-14361,CVE-2020-14362 JIRA References: Sources used: SUSE Linux Enterprise Server 11-SP4-LTSS (src): xorg-x11-server-7.4-27.122.29.1 SUSE Linux Enterprise Point of Sale 11-SP3 (src): xorg-x11-server-7.4-27.122.29.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): xorg-x11-server-7.4-27.122.29.1 SUSE Linux Enterprise Debuginfo 11-SP3 (src): xorg-x11-server-7.4-27.122.29.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2020:2407-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1174910,1174913 CVE References: CVE-2020-14361,CVE-2020-14362 JIRA References: Sources used: SUSE Linux Enterprise Software Development Kit 12-SP5 (src): xorg-x11-server-1.19.6-10.12.1 SUSE Linux Enterprise Server 12-SP5 (src): xorg-x11-server-1.19.6-10.12.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2020:2452-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1174910,1174913 CVE References: CVE-2020-14361,CVE-2020-14362 JIRA References: Sources used: SUSE Linux Enterprise Workstation Extension 15-SP2 (src): xorg-x11-server-1.20.3-22.5.5.1 SUSE Linux Enterprise Module for Development Tools 15-SP2 (src): xorg-x11-server-1.20.3-22.5.5.1 SUSE Linux Enterprise Module for Basesystem 15-SP2 (src): xorg-x11-server-1.20.3-22.5.5.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2020:2481-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1174910,1174913 CVE References: CVE-2020-14361,CVE-2020-14362 JIRA References: Sources used: SUSE Linux Enterprise Workstation Extension 15-SP1 (src): xorg-x11-server-1.20.3-14.5.5.2 SUSE Linux Enterprise Module for Development Tools 15-SP1 (src): xorg-x11-server-1.20.3-14.5.5.2 SUSE Linux Enterprise Module for Basesystem 15-SP1 (src): xorg-x11-server-1.20.3-14.5.5.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. openSUSE-SU-2020:1374-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1174910,1174913 CVE References: CVE-2020-14361,CVE-2020-14362 JIRA References: Sources used: openSUSE Leap 15.1 (src): xorg-x11-server-1.20.3-lp151.4.6.1 openSUSE-SU-2020:1376-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1174910,1174913 CVE References: CVE-2020-14361,CVE-2020-14362 JIRA References: Sources used: openSUSE Leap 15.2 (src): xorg-x11-server-1.20.3-lp152.8.6.1 reelased |