CVE-2018-14665

Description

A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.

Risk Information

Base Score
6.6
MODERATE
Vector
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
14.457

Associated Vulnerability

VulnerabilityOS Platform
X.Org X11 server (USN-3802-1) xserver-xorg-core_1.19.6-1ubuntu4.2_i386.debLinux
X.Org X11 server (USN-3802-1) xserver-xorg-core_1.19.6-1ubuntu4.2_amd64.debLinux
X.Org X11 server (USN-3802-1) xserver-xorg-core_1.20.1-3ubuntu2.1_i386.debLinux
X.Org X11 server (USN-3802-1) xserver-xorg-core_1.20.1-3ubuntu2.1_amd64.debLinux
Xorg-x11-server security update (CESA-2018:3410) xorg-x11-server-Xdmx-1.20.1-5.1.el7.x86_64.rpmLinux
Xorg-x11-server security update (CESA-2018:3410) xorg-x11-server-Xorg-1.20.1-5.1.el7.x86_64.rpmLinux
Xorg-x11-server security update (CESA-2018:3410) xorg-x11-server-Xvfb-1.20.1-5.1.el7.x86_64.rpmLinux
Xorg-x11-server security update (CESA-2018:3410) xorg-x11-server-Xnest-1.20.1-5.1.el7.x86_64.rpmLinux
Xorg-x11-server security update (CESA-2018:3410) xorg-x11-server-devel-1.20.1-5.1.el7.i686.rpmLinux
Xorg-x11-server security update (CESA-2018:3410) xorg-x11-server-devel-1.20.1-5.1.el7.x86_64.rpmLinux
Xorg-x11-server security update (CESA-2018:3410) xorg-x11-server-Xephyr-1.20.1-5.1.el7.x86_64.rpmLinux
Xorg-x11-server security update (CESA-2018:3410) xorg-x11-server-common-1.20.1-5.1.el7.x86_64.rpmLinux
Xorg-x11-server security update (CESA-2018:3410) xorg-x11-server-source-1.20.1-5.1.el7.noarch.rpmLinux
Xorg-x11-server security update (CESA-2018:3410) xorg-x11-server-Xwayland-1.20.1-5.1.el7.x86_64.rpmLinux
(RHSA-2018:3410) xorg-x11-server security update xorg-x11-server-Xdmx-1.20.1-5.1.el7.x86_64.rpmLinux
(RHSA-2018:3410) xorg-x11-server security update xorg-x11-server-Xephyr-1.20.1-5.1.el7.x86_64.rpmLinux
(RHSA-2018:3410) xorg-x11-server security update xorg-x11-server-Xnest-1.20.1-5.1.el7.x86_64.rpmLinux
(RHSA-2018:3410) xorg-x11-server security update xorg-x11-server-Xorg-1.20.1-5.1.el7.x86_64.rpmLinux
(RHSA-2018:3410) xorg-x11-server security update xorg-x11-server-Xvfb-1.20.1-5.1.el7.x86_64.rpmLinux
(RHSA-2018:3410) xorg-x11-server security update xorg-x11-server-Xwayland-1.20.1-5.1.el7.x86_64.rpmLinux
(RHSA-2018:3410) xorg-x11-server security update xorg-x11-server-common-1.20.1-5.1.el7.x86_64.rpmLinux
(RHSA-2018:3410) xorg-x11-server security update xorg-x11-server-devel-1.20.1-5.1.el7.i686.rpmLinux
(RHSA-2018:3410) xorg-x11-server security update xorg-x11-server-devel-1.20.1-5.1.el7.x86_64.rpmLinux
(RHSA-2018:3410) xorg-x11-server security update xorg-x11-server-source-1.20.1-5.1.el7.noarch.rpmLinux
SUSE-SU-2018:3456-1(SUSE Linux Enterprise Server 11-SP4 ) xorg-x11-server-7.4-27.122.21.1.i586.rpmLinux
SUSE-SU-2018:3456-1(SUSE Linux Enterprise Server 11-SP4 ) xorg-x11-server-7.4-27.122.21.1.x86_64.rpmLinux
SUSE-SU-2018:3456-1(SUSE Linux Enterprise Server 11-SP4 ) xorg-x11-server-extra-7.4-27.122.21.1.i586.rpmLinux
SUSE-SU-2018:3456-1(SUSE Linux Enterprise Server 11-SP4 ) xorg-x11-server-extra-7.4-27.122.21.1.x86_64.rpmLinux
SUSE-SU-2018:3456-1(SUSE Linux Enterprise Server 11-SP4 ) xorg-x11-Xvnc-7.4-27.122.21.1.i586.rpmLinux
SUSE-SU-2018:3456-1(SUSE Linux Enterprise Server 11-SP4 ) xorg-x11-Xvnc-7.4-27.122.21.1.x86_64.rpmLinux
Xorg-x11-server-Xwayland update (ELSA-2018-3410) xorg-x11-server-Xwayland-1.20.1-5.1.el7.x86_64.rpmLinux
Gdm update (ELSA-2019-2079) gdm-3.28.2-16.el7.i686.rpmLinux
Gdm update (ELSA-2019-2079) gdm-3.28.2-16.el7.x86_64.rpmLinux
LibX11 update (ELSA-2019-2079) libX11-1.6.7-2.el7.i686.rpmLinux
LibX11 update (ELSA-2019-2079) libX11-1.6.7-2.el7.x86_64.rpmLinux
LibX11-common update (ELSA-2019-2079) libX11-common-1.6.7-2.el7.noarch.rpmLinux
LibX11-devel update (ELSA-2019-2079) libX11-devel-1.6.7-2.el7.i686.rpmLinux
LibX11-devel update (ELSA-2019-2079) libX11-devel-1.6.7-2.el7.x86_64.rpmLinux
Libxkbcommon update (ELSA-2019-2079) libxkbcommon-0.7.1-3.el7.i686.rpmLinux
Libxkbcommon update (ELSA-2019-2079) libxkbcommon-0.7.1-3.el7.x86_64.rpmLinux
Libxkbcommon-devel update (ELSA-2019-2079) libxkbcommon-devel-0.7.1-3.el7.i686.rpmLinux
Libxkbcommon-devel update (ELSA-2019-2079) libxkbcommon-devel-0.7.1-3.el7.x86_64.rpmLinux
Libxkbcommon-x11 update (ELSA-2019-2079) libxkbcommon-x11-0.7.1-3.el7.i686.rpmLinux
Libxkbcommon-x11 update (ELSA-2019-2079) libxkbcommon-x11-0.7.1-3.el7.x86_64.rpmLinux
Mesa-libGLw update (ELSA-2019-2079) mesa-libGLw-8.0.0-5.el7.i686.rpmLinux
Mesa-libGLw update (ELSA-2019-2079) mesa-libGLw-8.0.0-5.el7.x86_64.rpmLinux
Mesa-libGLw-devel update (ELSA-2019-2079) mesa-libGLw-devel-8.0.0-5.el7.i686.rpmLinux
Mesa-libGLw-devel update (ELSA-2019-2079) mesa-libGLw-devel-8.0.0-5.el7.x86_64.rpmLinux
Xorg-x11-drv-ati update (ELSA-2019-2079) xorg-x11-drv-ati-19.0.1-2.el7.x86_64.rpmLinux
Xorg-x11-drv-vesa update (ELSA-2019-2079) xorg-x11-drv-vesa-2.4.0-3.el7.x86_64.rpmLinux
Xorg-x11-drv-wacom update (ELSA-2019-2079) xorg-x11-drv-wacom-0.36.1-3.el7.x86_64.rpmLinux
Xorg-x11-server-Xephyr update (ELSA-2019-2079) xorg-x11-server-Xephyr-1.20.4-7.el7.x86_64.rpmLinux
Xorg-x11-server-Xorg update (ELSA-2019-2079) xorg-x11-server-Xorg-1.20.4-7.el7.x86_64.rpmLinux
Xorg-x11-server-common update (ELSA-2019-2079) xorg-x11-server-common-1.20.4-7.el7.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234