Privilege escalation in X.org Server - CVE-2018-14665

 

Privilege escalation in X.org Server - CVE-2018-14665

Published: October 25, 2018 / Updated: June 17, 2021


Vulnerability identifier: #VU15538
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Clear
CVE-ID: CVE-2018-14665
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: Public exploit is available
Affected software:
X.org Server
Arch Linux
Gentoo Linux
Debian Linux
IBM AIX
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power
Opensuse
Fedora
xorg-server (Alpine package)
xorg-x11-server
Dynamic System Analysis (DSA) Preboot

Detailed vulnerability description

The vulnerability allows a local user to gain elevated privileges on the target system.

The vulnerability exists due to improper handling of two command-line options, namely -logfile and -modulepath. A local user can specify a '-modulepath' argument with an insecure path to create, overwrite or delete any files with root privileges.


How to mitigate CVE-2018-14665

Update to version 1.20.3.

Sources