
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-14360 is a security vulnerability discovered in the X.Org Server before version 1.20.10. The vulnerability involves an out-of-bounds access in the XkbSetMap function that could potentially lead to privilege escalation. The flaw was discovered by Jan-Niklas Sohn working with Trend Micro Zero Day Initiative and was publicly disclosed on December 1, 2020 (X.Org Announce).
The vulnerability stems from insufficient checks on the lengths of the XkbSetMap request, which can lead to out-of-bounds memory accesses in the X server. The issue affects systems where the X server is running with privileged access. The vulnerability has been assigned a CVSS 3.1 base score of 7.8 (High), with the following vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (Ubuntu Security).
The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. On systems where the X server runs with root privileges, this vulnerability could lead to privilege escalation for authorized clients (X.Org Announce).
The vulnerability requires local access and low privileges to exploit. It affects authorized clients on systems where the X server is running with privileged access. The attack complexity is considered low, requiring no user interaction (Ubuntu Security).
The vulnerability was fixed in X.Org Server version 1.20.10. A patch was committed to the xorg server git repository with commit 446ff2d3177087b8173fa779fa5b77a2a128988b, which implements careful checking of SetMap request length to avoid out-of-bounds memory accesses (X.Org Announce).
Red Hat rated this update as having a security impact of Important. However, they noted that the Xorg server in Red Hat Enterprise Linux 8 does not run with root privileges, thus this flaw was rated as having a moderate impact on that platform (Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."