vendor:
xorg-x11-server
by:
Marco Ivaldi
6.6
CVSS
MEDIUM
Privilege Escalation
269
CWE
Product Name: xorg-x11-server
Affected Version From: xorg-x11-server 1.19.0
Affected Version To: xorg-x11-server 1.20.2
Patch Exists: YES
Related CWE: CVE-2018-14665
CPE: a:xorg:xorg-x11-server
Metasploit:
https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp2-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp3-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/ibm-aix-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp5-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp8-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2018-14665/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2018-14665/
Other Scripts:
N/A
Platforms Tested: OpenBSD 6.3 and 6.4
2018
xorg-x11-server 1.20.3 – Privilege Escalation
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.
Mitigation:
Upgrade to xorg-x11-server 1.20.3 or later.