Security restrictions bypass in X.org Server - CVE-2020-25697
Published: November 10, 2020 / Updated: December 2, 2020
Vulnerability identifier: #VU48239
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-25697
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the way X.org server handles authentication requests. A local user can impersonate the X.org server and trick the victim into providing credentials to a rouge application under attackers control.
Affected software
X.org Server
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Basesystem Module
openSUSE Leap
xtrans
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Basesystem Module
openSUSE Leap
xtrans
How to mitigate CVE-2020-25697
Install update from vendor's website.
X.org Server - update to 1.20.10
xtrans - addressed in versions 1.3.5-5.3.1, 1.3.5-150000.3.3.1
xtrans - addressed in versions 1.3.5-5.3.1, 1.3.5-150000.3.3.1