CVE-2020-14363
CVE-2020-14363
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 7.8EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
11 set 2020Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application compiled with libX11 to crash, or in some cases, result in arbitrary code execution. The highest threat from this flaw is to confidentiality, integrity as well as system availability.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
The X11 Project · libX11Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14363https://github.com/Ruia-ruia/Exploits/blob/master/DFX11details.txthttps://github.com/Ruia-ruia/Exploits/blob/master/x11doublefree.shhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7AVXCQOSCAPKYYHFIJAZ6E2C7LJBTLXF/https://lists.x.org/archives/xorg-announce/2020-August/003056.htmlhttps://usn.ubuntu.com/4487-2/