ALPINE-CVE-2018-14665 PUBLISHED CVSS 6.599999904632568 MEDIUM

A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.

Risk Scores

CVSS v3.0
6.599999904632568
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alpine:v3.9xorg-server0, 1.10.0-r0, 1.10.0.901-r0
Alpine:v3.8xorg-server1.10.0.902-r0, 0, 1.10.0-r0
Alpine:v3.11xorg-server1.9.4-r1, 1.11.0-r0, 1.10.4-r0
Alpine:v3.12xorg-server1.19.3-r0, 1.10.0-r0, 1.10.0.901-r0
Alpine:v3.10xorg-server1.6.2-r1, 1.18.4-r0, 1.7.3.901-r0
Alpine:v3.7xorg-server1.9.0-r1, 0, 1.10.0-r0
Alpine:v3.6xorg-server1.9.4-r1, 1.9.4-r0, 1.9.3.902-r0

Timeline

References

Open in Interactive Console →