A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.
{ "vanir_signatures": [ { "id": "CVE-2018-14665-22639977", "source": "https://gitlab.freedesktop.org/xorg/xserver@8a59e3b7dbb30532a7c3769c555e00d7c4301170", "deprecated": false, "signature_version": "v1", "signature_type": "Function", "digest": { "length": 6630.0, "function_hash": "315373064620892594551951638009703833680" }, "target": { "file": "hw/xfree86/common/xf86Init.c", "function": "ddxProcessArgument" } }, { "id": "CVE-2018-14665-6550486b", "source": "https://gitlab.freedesktop.org/xorg/xserver@50c0cf885a6e91c0ea71fb49fa8f1b7c86fe330e", "deprecated": false, "signature_version": "v1", "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "65873069307278292652010531175368615420", "284923232927484381038688238309080919142", "27624637168183375727967830732217204166", "235860324613668966512981938403285548298", "183732425723223922100410593710392118164", "114508074504614284615304547286231225643", "315439724826352396352105082473061468447", "212627248673392263212831660654490005750", "95330500942765008061279670440426547946", "56839145749456828219969817469731032700", "213388443174132321590396988505480979115" ] }, "target": { "file": "hw/xfree86/common/xf86Init.c" } }, { "id": "CVE-2018-14665-78795323", "source": "https://gitlab.freedesktop.org/xorg/xserver@8a59e3b7dbb30532a7c3769c555e00d7c4301170", "deprecated": false, "signature_version": "v1", "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "65873069307278292652010531175368615420", "284923232927484381038688238309080919142", "27624637168183375727967830732217204166", "235860324613668966512981938403285548298", "183732425723223922100410593710392118164", "114508074504614284615304547286231225643", "315439724826352396352105082473061468447", "212627248673392263212831660654490005750", "95330500942765008061279670440426547946", "56839145749456828219969817469731032700", "213388443174132321590396988505480979115" ] }, "target": { "file": "hw/xfree86/common/xf86Init.c" } }, { "id": "CVE-2018-14665-9355e2b1", "source": "https://gitlab.freedesktop.org/xorg/xserver@50c0cf885a6e91c0ea71fb49fa8f1b7c86fe330e", "deprecated": false, "signature_version": "v1", "signature_type": "Function", "digest": { "length": 6537.0, "function_hash": "183506005408712373153446637987835782518" }, "target": { "file": "hw/xfree86/common/xf86Init.c", "function": "ddxProcessArgument" } } ] }