vulnerability

Red Hat: CVE-2018-14600: Moderate: Xorg security and bug fix update (RHSA-2019:2079)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Aug 24, 2018
Added
Aug 7, 2019
Modified
Jul 9, 2025

Description

An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as signed instead of unsigned, resulting in an out-of-bounds write (of up to 128 bytes), leading to DoS or remote code execution.

Solutions

no-fix-redhat-rpm-packageredhat-upgrade-gdmredhat-upgrade-gdm-debuginforedhat-upgrade-gdm-develredhat-upgrade-gdm-pam-extensions-develredhat-upgrade-libx11redhat-upgrade-libx11-commonredhat-upgrade-libx11-debuginforedhat-upgrade-libx11-develredhat-upgrade-libxkbcommonredhat-upgrade-libxkbcommon-debuginforedhat-upgrade-libxkbcommon-develredhat-upgrade-libxkbcommon-x11redhat-upgrade-libxkbcommon-x11-develredhat-upgrade-mesa-libglwredhat-upgrade-mesa-libglw-debuginforedhat-upgrade-mesa-libglw-develredhat-upgrade-xorg-x11-drv-atiredhat-upgrade-xorg-x11-drv-ati-debuginforedhat-upgrade-xorg-x11-drv-vesaredhat-upgrade-xorg-x11-drv-vesa-debuginforedhat-upgrade-xorg-x11-drv-wacomredhat-upgrade-xorg-x11-drv-wacom-debuginforedhat-upgrade-xorg-x11-drv-wacom-develredhat-upgrade-xorg-x11-server-commonredhat-upgrade-xorg-x11-server-debuginforedhat-upgrade-xorg-x11-server-develredhat-upgrade-xorg-x11-server-sourceredhat-upgrade-xorg-x11-server-xdmxredhat-upgrade-xorg-x11-server-xephyrredhat-upgrade-xorg-x11-server-xnestredhat-upgrade-xorg-x11-server-xorgredhat-upgrade-xorg-x11-server-xvfbredhat-upgrade-xorg-x11-server-xwayland
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.