7.5

CVE-2018-14598

An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in which the first string overflows, causing a variable to be set to NULL that will be freed later on, leading to DoS (segmentation fault).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
X.Org ≫ Libx11 Version <= 1.6.5
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Debian ≫ Debian Linux Version 8.0
Fedoraproject ≫ Fedora Version 28
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.23% 0.898
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://usn.ubuntu.com/3758-1/
Third Party Advisory
https://usn.ubuntu.com/3758-2/
Third Party Advisory
http://www.openwall.com/lists/oss-security/2018/08/21/6
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/105177
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1041543
Third Party Advisory
VDB Entry
https://access.redhat.com/errata/RHSA-2019:2079
https://bugzilla.suse.com/show_bug.cgi?id=1102073
Patch
Third Party Advisory
Issue Tracking
https://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=e83722768fd5c467ef61fa159e8c6278770b45c2
Patch
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/08/msg00030.html
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YGARUV66TS5OOSLR5A76BUB7SDV6GO4F/
https://lists.x.org/archives/xorg-announce/2018-August/002916.html
Third Party Advisory
https://security.gentoo.org/glsa/201811-01
Third Party Advisory