CVE Vulnerabilities

CVE-2020-14346

Integer Underflow (Wrap or Wraparound)

Published: Sep 15, 2020 | Modified: Nov 08, 2022
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.8 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Weakness

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Affected Software

Name Vendor Start Version End Version
Xorg-server X.org * 1.20.9 (excluding)
Red Hat Enterprise Linux 6 RedHat xorg-x11-server-0:1.17.4-18.el6_10 *
Red Hat Enterprise Linux 7 RedHat xorg-x11-server-0:1.20.4-12.el7_9 *
Red Hat Enterprise Linux 8 RedHat egl-wayland-0:1.1.5-3.el8 *
Red Hat Enterprise Linux 8 RedHat libdrm-0:2.4.103-1.el8 *
Red Hat Enterprise Linux 8 RedHat libglvnd-1:1.3.2-1.el8 *
Red Hat Enterprise Linux 8 RedHat libinput-0:1.16.3-1.el8 *
Red Hat Enterprise Linux 8 RedHat libwacom-0:1.6-2.el8 *
Red Hat Enterprise Linux 8 RedHat libX11-0:1.6.8-4.el8 *
Red Hat Enterprise Linux 8 RedHat mesa-0:20.3.3-2.el8 *
Red Hat Enterprise Linux 8 RedHat xorg-x11-drivers-0:7.7-30.el8 *
Red Hat Enterprise Linux 8 RedHat xorg-x11-server-0:1.20.10-1.el8 *
Xorg Ubuntu trusty *
Xorg-server Ubuntu bionic *
Xorg-server Ubuntu devel *
Xorg-server Ubuntu focal *
Xorg-server Ubuntu trusty *
Xorg-server Ubuntu trusty/esm *
Xorg-server Ubuntu upstream *
Xorg-server Ubuntu xenial *
Xorg-server-hwe-16.04 Ubuntu upstream *
Xorg-server-hwe-16.04 Ubuntu xenial *
Xorg-server-hwe-18.04 Ubuntu bionic *
Xorg-server-hwe-18.04 Ubuntu upstream *
Xorg-server-lts-utopic Ubuntu trusty *
Xorg-server-lts-vivid Ubuntu trusty *
Xorg-server-lts-wily Ubuntu trusty *
Xorg-server-lts-xenial Ubuntu trusty *

References