{
  "threat_severity" : "Important",
  "public_date" : "2020-08-25T00:00:00Z",
  "bugzilla" : {
    "description" : "libX11: integer overflow leads to double free in locale handling",
    "id" : "1872473",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1872473"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-190",
  "details" : [ "An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application compiled with libX11 to crash, or in some cases, result in arbitrary code execution. The highest threat from this flaw is to confidentiality, integrity as well as system availability.", "An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application compiled with libX11 to crash, or in some cases, result in arbitrary code execution. The highest threat from this flaw is to confidentiality, integrity as well as system availability." ],
  "statement" : "Xorg server does not run with root privileges in Red Hat Enterprise Linux 8. Therefore this flaw has been rated as having a moderate impact for Red Hat Enterprise Linux 8.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2020-11-05T00:00:00Z",
    "advisory" : "RHSA-2020:4946",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "libX11-0:1.6.4-4.el6_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2020-11-04T00:00:00Z",
    "advisory" : "RHSA-2020:4908",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libX11-0:1.6.7-3.el7_9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2021-05-18T00:00:00Z",
    "advisory" : "RHSA-2021:1804",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "egl-wayland-0:1.1.5-3.el8",
    "impact" : "moderate"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2021-05-18T00:00:00Z",
    "advisory" : "RHSA-2021:1804",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "libdrm-0:2.4.103-1.el8",
    "impact" : "moderate"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2021-05-18T00:00:00Z",
    "advisory" : "RHSA-2021:1804",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "libglvnd-1:1.3.2-1.el8",
    "impact" : "moderate"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2021-05-18T00:00:00Z",
    "advisory" : "RHSA-2021:1804",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "libinput-0:1.16.3-1.el8",
    "impact" : "moderate"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2021-05-18T00:00:00Z",
    "advisory" : "RHSA-2021:1804",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "libwacom-0:1.6-2.el8",
    "impact" : "moderate"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2021-05-18T00:00:00Z",
    "advisory" : "RHSA-2021:1804",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "libX11-0:1.6.8-4.el8",
    "impact" : "moderate"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2021-05-18T00:00:00Z",
    "advisory" : "RHSA-2021:1804",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "mesa-0:20.3.3-2.el8",
    "impact" : "moderate"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2021-05-18T00:00:00Z",
    "advisory" : "RHSA-2021:1804",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "xorg-x11-drivers-0:7.7-30.el8",
    "impact" : "moderate"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2021-05-18T00:00:00Z",
    "advisory" : "RHSA-2021:1804",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "xorg-x11-server-0:1.20.10-1.el8",
    "impact" : "moderate"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 5",
    "fix_state" : "Out of support scope",
    "package_name" : "libX11",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2020-14363\nhttps://nvd.nist.gov/vuln/detail/CVE-2020-14363\nhttps://lists.x.org/archives/xorg-announce/2020-August/003056.html" ],
  "name" : "CVE-2020-14363",
  "csaw" : false
}