SB2020081021 - Privilege escalation in libX11 library
Published: August 10, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Integer overflow (CVE-ID: CVE-2020-14344)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to integer overflow in the X Input Method (XIM) client in libX11. A local user can run a specially crafted program, trigger integer overflow and execute arbitrary code on the system with elevated privileges.
Remediation
Install update from vendor's website.
References
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00015.html
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14344
- https://lists.x.org/archives/xorg-announce/2020-July/003050.html
- https://www.openwall.com/lists/oss-security/2020/07/31/1