CVE-2020-14347

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-14347
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-14347.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-14347
Related
Published
2020-08-05T14:15:12Z
Modified
2024-10-12T06:00:48.313004Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.

References

Affected packages

Alpine:v3.10 / xorg-server

Package

Name
xorg-server
Purl
pkg:apk/alpine/xorg-server?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.20.5-r1

Affected versions

1.*

1.6.0-r0
1.6.0-r1
1.6.0-r2
1.6.0-r3
1.6.0-r4
1.6.1-r0
1.6.1-r1
1.6.1-r2
1.6.1-r3
1.6.2-r0
1.6.2-r1
1.6.3-r0
1.6.3-r1
1.7.0.901-r1
1.7.1-r0
1.7.3.901-r0
1.7.3.902-r0
1.7.4.901-r0
1.7.6-r0
1.7.6-r1
1.7.6-r2
1.7.7-r0
1.7.7-r1
1.9.0-r0
1.9.0-r1
1.9.0.901-r0
1.9.1-r0
1.9.2-r0
1.9.3-r0
1.9.3.901-r0
1.9.3.902-r0
1.9.4-r0
1.9.4-r1
1.10.0-r0
1.10.0.901-r0
1.10.0.902-r0
1.10.1-r0
1.10.1-r1
1.10.2-r0
1.10.3-r0
1.10.4-r0
1.11.0-r0
1.11.1-r0
1.11.1-r1
1.11.1.902-r0
1.11.2-r0
1.11.3-r0
1.11.4-r0
1.11.4-r1
1.12.0-r0
1.12.1-r0
1.12.1-r1
1.12.1.902-r0
1.12.2-r0
1.12.3-r0
1.12.4-r0
1.13.0-r0
1.13.1-r0
1.13.2-r0
1.13.2-r1
1.13.2-r2
1.14.0-r0
1.14.0-r1
1.14.1-r0
1.14.2-r0
1.14.3-r0
1.14.4-r0
1.14.5-r0
1.15.0-r0
1.15.0-r1
1.15.1-r0
1.15.2-r0
1.16.0-r0
1.16.0-r1
1.16.0-r2
1.16.1-r0
1.16.2-r0
1.16.2.901-r0
1.16.3-r0
1.17.1-r0
1.17.1-r1
1.17.1-r2
1.17.1-r3
1.17.2-r0
1.17.2-r1
1.17.2-r2
1.17.3-r0
1.17.4-r0
1.17.4-r1
1.18.0-r0
1.18.1-r0
1.18.2-r0
1.18.3-r0
1.18.4-r0
1.18.4-r1
1.18.4-r2
1.18.4-r3
1.18.4-r4
1.19.3-r0
1.19.3-r1
1.19.3-r2
1.19.3-r3
1.19.3-r4
1.19.5-r0
1.19.6-r0
1.19.6-r1
1.19.6-r2
1.19.6-r3
1.20.0-r0
1.20.1-r0
1.20.3-r0
1.20.3-r1
1.20.4-r0
1.20.5-r0

Alpine:v3.11 / xorg-server

Package

Name
xorg-server
Purl
pkg:apk/alpine/xorg-server?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.20.6-r1

Affected versions

1.*

1.6.0-r0
1.6.0-r1
1.6.0-r2
1.6.0-r3
1.6.0-r4
1.6.1-r0
1.6.1-r1
1.6.1-r2
1.6.1-r3
1.6.2-r0
1.6.2-r1
1.6.3-r0
1.6.3-r1
1.7.0.901-r1
1.7.1-r0
1.7.3.901-r0
1.7.3.902-r0
1.7.4.901-r0
1.7.6-r0
1.7.6-r1
1.7.6-r2
1.7.7-r0
1.7.7-r1
1.9.0-r0
1.9.0-r1
1.9.0.901-r0
1.9.1-r0
1.9.2-r0
1.9.3-r0
1.9.3.901-r0
1.9.3.902-r0
1.9.4-r0
1.9.4-r1
1.10.0-r0
1.10.0.901-r0
1.10.0.902-r0
1.10.1-r0
1.10.1-r1
1.10.2-r0
1.10.3-r0
1.10.4-r0
1.11.0-r0
1.11.1-r0
1.11.1-r1
1.11.1.902-r0
1.11.2-r0
1.11.3-r0
1.11.4-r0
1.11.4-r1
1.12.0-r0
1.12.1-r0
1.12.1-r1
1.12.1.902-r0
1.12.2-r0
1.12.3-r0
1.12.4-r0
1.13.0-r0
1.13.1-r0
1.13.2-r0
1.13.2-r1
1.13.2-r2
1.14.0-r0
1.14.0-r1
1.14.1-r0
1.14.2-r0
1.14.3-r0
1.14.4-r0
1.14.5-r0
1.15.0-r0
1.15.0-r1
1.15.1-r0
1.15.2-r0
1.16.0-r0
1.16.0-r1
1.16.0-r2
1.16.1-r0
1.16.2-r0
1.16.2.901-r0
1.16.3-r0
1.17.1-r0
1.17.1-r1
1.17.1-r2
1.17.1-r3
1.17.2-r0
1.17.2-r1
1.17.2-r2
1.17.3-r0
1.17.4-r0
1.17.4-r1
1.18.0-r0
1.18.1-r0
1.18.2-r0
1.18.3-r0
1.18.4-r0
1.18.4-r1
1.18.4-r2
1.18.4-r3
1.18.4-r4
1.19.3-r0
1.19.3-r1
1.19.3-r2
1.19.3-r3
1.19.3-r4
1.19.5-r0
1.19.6-r0
1.19.6-r1
1.19.6-r2
1.19.6-r3
1.20.0-r0
1.20.1-r0
1.20.3-r0
1.20.3-r1
1.20.4-r0
1.20.5-r0
1.20.6-r0

Alpine:v3.12 / xorg-server

Package

Name
xorg-server
Purl
pkg:apk/alpine/xorg-server?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.20.8-r4

Affected versions

1.*

1.6.0-r0
1.6.0-r1
1.6.0-r2
1.6.0-r3
1.6.0-r4
1.6.1-r0
1.6.1-r1
1.6.1-r2
1.6.1-r3
1.6.2-r0
1.6.2-r1
1.6.3-r0
1.6.3-r1
1.7.0.901-r1
1.7.1-r0
1.7.3.901-r0
1.7.3.902-r0
1.7.4.901-r0
1.7.6-r0
1.7.6-r1
1.7.6-r2
1.7.7-r0
1.7.7-r1
1.9.0-r0
1.9.0-r1
1.9.0.901-r0
1.9.1-r0
1.9.2-r0
1.9.3-r0
1.9.3.901-r0
1.9.3.902-r0
1.9.4-r0
1.9.4-r1
1.10.0-r0
1.10.0.901-r0
1.10.0.902-r0
1.10.1-r0
1.10.1-r1
1.10.2-r0
1.10.3-r0
1.10.4-r0
1.11.0-r0
1.11.1-r0
1.11.1-r1
1.11.1.902-r0
1.11.2-r0
1.11.3-r0
1.11.4-r0
1.11.4-r1
1.12.0-r0
1.12.1-r0
1.12.1-r1
1.12.1.902-r0
1.12.2-r0
1.12.3-r0
1.12.4-r0
1.13.0-r0
1.13.1-r0
1.13.2-r0
1.13.2-r1
1.13.2-r2
1.14.0-r0
1.14.0-r1
1.14.1-r0
1.14.2-r0
1.14.3-r0
1.14.4-r0
1.14.5-r0
1.15.0-r0
1.15.0-r1
1.15.1-r0
1.15.2-r0
1.16.0-r0
1.16.0-r1
1.16.0-r2
1.16.1-r0
1.16.2-r0
1.16.2.901-r0
1.16.3-r0
1.17.1-r0
1.17.1-r1
1.17.1-r2
1.17.1-r3
1.17.2-r0
1.17.2-r1
1.17.2-r2
1.17.3-r0
1.17.4-r0
1.17.4-r1
1.18.0-r0
1.18.1-r0
1.18.2-r0
1.18.3-r0
1.18.4-r0
1.18.4-r1
1.18.4-r2
1.18.4-r3
1.18.4-r4
1.19.3-r0
1.19.3-r1
1.19.3-r2
1.19.3-r3
1.19.3-r4
1.19.5-r0
1.19.6-r0
1.19.6-r1
1.19.6-r2
1.19.6-r3
1.20.0-r0
1.20.1-r0
1.20.3-r0
1.20.3-r1
1.20.4-r0
1.20.5-r0
1.20.6-r0
1.20.6-r1
1.20.6-r2
1.20.7-r0
1.20.7-r1
1.20.7-r2
1.20.7-r3
1.20.7-r4
1.20.7-r5
1.20.8-r0
1.20.8-r1
1.20.8-r2
1.20.8-r3

Debian:11 / xorg-server

Package

Name
xorg-server
Purl
pkg:deb/debian/xorg-server?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:1.20.9-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / xorg-server

Package

Name
xorg-server
Purl
pkg:deb/debian/xorg-server?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:1.20.9-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / xorg-server

Package

Name
xorg-server
Purl
pkg:deb/debian/xorg-server?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:1.20.9-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / gitlab.freedesktop.org/xorg/xserver

Affected ranges

Type
GIT
Repo
https://gitlab.freedesktop.org/xorg/xserver
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

DAMAGE-XFIXES-BASE
DRI-XFree86-4_3_99_12-merge
DRI-trunk-20040613
DRI-trunk-20040721
DRM-1_0_5
DRM-20040613
DRM-20040721
DRM-20050615
DRM-20051017
DRM-2_0_0
Domain-base
Domain-sync1
Domain-sync2
Domain-sync3
Domain-sync4
MODULAR_COPY
PRE_xf86-4_3_0_1
XACE-SELINUX-BASE
XACE-SELINUX-MERGE
XEVIE-BASE
XEVIE-MERGE
XORG-6_7_99_1
XORG-6_7_99_2
XORG-6_7_99_901
XORG-6_7_99_902
XORG-6_7_99_903
XORG-6_7_99_904
XORG-6_8_0
XORG-6_8_99_1
XORG-6_8_99_10
XORG-6_8_99_11
XORG-6_8_99_12
XORG-6_8_99_13
XORG-6_8_99_14
XORG-6_8_99_15
XORG-6_8_99_16
XORG-6_8_99_2
XORG-6_8_99_3
XORG-6_8_99_4
XORG-6_8_99_5
XORG-6_8_99_6
XORG-6_8_99_7
XORG-6_8_99_8
XORG-6_8_99_9
XORG-6_8_99_900
XORG-6_8_99_901
XORG-6_8_99_902
XORG-6_8_99_903
XORG-6_99_99_900
XORG-6_99_99_901
XORG-6_99_99_902
XORG-6_99_99_903
XORG-6_99_99_904
XORG-7_0
XORG-7_0_99_901
XORG-CURRENT-CLOSED
XORG-CURRENT-premerge-release-1
XORG-MAIN
XORG-RELEASE-1-BASE
add-Xi
ah-20021030
ah-20021030-postdri
before-mesa-4_0-import
before_20040421_xprint_branch_landing
dhd-20010328
dhd-20010817
dhd-20020916
dri-0-1-branchpoint
dri-20020129-merge
dri-20020222-merge
kdrive-initial-import
keithp
lg3d-base
pre-R651-import
pre-xgldrop-merge
sco_port_update-base
xf-3_9_16Z
xf-3_9_16Za
xf-3_9_16d
xf-3_9_16e
xf-3_9_16f
xf-3_9_17
xf-3_9_17Z
xf-3_9_17a
xf-3_9_17b
xf-3_9_17c
xf-3_9_17d
xf-3_9_17e
xf-3_9_17f
xf-3_9_18
xf-3_9_18Z
xf-3_9_18Za
xf-3_9_18a
xf-3_9_18b
xf-4_0
xf-4_0-bindist
xf-4_0Z
xf-4_0_1
xf-4_0_1-bindist
xf-4_0_1Z
xf-4_0_1Za
xf-4_0_1Zb
xf-4_0_1Zc
xf-4_0_1a
xf-4_0_1b
xf-4_0_1c
xf-4_0_1d
xf-4_0_1e
xf-4_0_1f
xf-4_0_1g
xf-4_0_1h
xf-4_0_2
xf-4_0_2-bindist
xf-4_0_99_1
xf-4_0_99_2
xf-4_0_99_3
xf-4_0_99_900
xf-4_0a
xf-4_0b
xf-4_0c
xf-4_0d
xf-4_0e
xf-4_0f
xf-4_0g
xf-4_1_99_1
xf-4_1_99_2
xf-4_1_99_3
xf-4_1_99_4
xf-4_1_99_5
xf-4_1_99_6
xf-4_1_99_7
xf-4_2-bp
xf-4_2_0
xf-4_2_0-bindist
xf-4_2_0-bindist-1
xf-4_2_0_1
xf-4_2_1
xf-4_2_1_1
xf-4_2_99_1
xf-4_2_99_2
xf-4_2_99_3
xf-4_2_99_4
xf-4_2_99_901
xf-4_2_99_902
xf-4_3_0
xf-4_3_0_1
xf-4_3_99_1
xf-4_3_99_2
xf-4_3_99_3
xf-4_3_99_4
xf-4_3_99_5
xf-4_3_99_6
xf86-012804-2330
xf86-4_3_0_1
xf86-4_3_99_16
xf86-4_3_99_901
xf86-4_3_99_902
xf86-4_3_99_903
xf86-4_3_99_903_special
xf86-4_4_0
xf86-4_4_99_1
xfixes_2_branchpoint
xorg-server-0_99_1
xorg-server-1_0_99_1
xorg-server-1_0_99_2
xorg-server-1_0_99_901
xorg-server-1_1_99_1
xorg-server-1_1_99_2

xorg-server-1.*

xorg-server-1.1.99.3
xorg-server-1.10.0
xorg-server-1.10.99.901
xorg-server-1.10.99.902
xorg-server-1.11.0
xorg-server-1.11.99.1
xorg-server-1.11.99.2
xorg-server-1.11.99.901
xorg-server-1.11.99.902
xorg-server-1.11.99.903
xorg-server-1.12.0
xorg-server-1.12.99.901
xorg-server-1.12.99.902
xorg-server-1.12.99.903
xorg-server-1.12.99.904
xorg-server-1.12.99.905
xorg-server-1.13.0
xorg-server-1.13.99.901
xorg-server-1.13.99.902
xorg-server-1.14.0
xorg-server-1.14.99.1
xorg-server-1.14.99.2
xorg-server-1.14.99.3
xorg-server-1.14.99.901
xorg-server-1.14.99.902
xorg-server-1.14.99.903
xorg-server-1.14.99.904
xorg-server-1.14.99.905
xorg-server-1.15.0
xorg-server-1.15.99.901
xorg-server-1.15.99.902
xorg-server-1.15.99.903
xorg-server-1.15.99.904
xorg-server-1.16.0
xorg-server-1.16.99.901
xorg-server-1.16.99.902
xorg-server-1.17.0
xorg-server-1.17.99.901
xorg-server-1.17.99.902
xorg-server-1.18.0
xorg-server-1.18.99.2
xorg-server-1.18.99.901
xorg-server-1.18.99.902
xorg-server-1.19.0
xorg-server-1.19.99.901
xorg-server-1.19.99.902
xorg-server-1.19.99.903
xorg-server-1.19.99.904
xorg-server-1.19.99.905
xorg-server-1.2.99.0
xorg-server-1.20.0
xorg-server-1.20.1
xorg-server-1.20.2
xorg-server-1.20.3
xorg-server-1.20.4
xorg-server-1.20.5
xorg-server-1.20.6
xorg-server-1.20.7
xorg-server-1.20.8
xorg-server-1.3.99.0
xorg-server-1.5.99.1
xorg-server-1.6.99.900
xorg-server-1.6.99.901
xorg-server-1.7.99.1
xorg-server-1.7.99.2
xorg-server-1.7.99.901
xorg-server-1.7.99.902
xorg-server-1.8.0
xorg-server-1.8.99.901
xorg-server-1.8.99.902
xorg-server-1.8.99.903
xorg-server-1.8.99.904
xorg-server-1.8.99.905
xorg-server-1.8.99.906
xorg-server-1.9.0
xorg-server-1.9.99.901
xorg-server-1.9.99.902
xorg-server-1.9.99.903