CVE-2020-25712 log

Source
Severity Medium
Remote No
Type Arbitrary code execution
Description
A security issue was discovered in xorg-server before 1.20.10. Insufficient checks on input of the XkbSetDeviceInfo request can lead to a buffer overflow on the head in the X server. This issue can lead to privilege escalation for authorized clients on systems where the X server is running privileged.
Group Package Affected Fixed Severity Status Ticket
AVG-1310 xorg-server 1.20.9.r21.g5c400cae1-2 1.20.10-1 Medium Fixed
Date Advisory Group Package Severity Type
05 Dec 2020 ASA-202012-6 AVG-1310 xorg-server Medium arbitrary code execution
References
https://www.openwall.com/lists/oss-security/2020/12/01/3
https://gitlab.freedesktop.org/xorg/xserver/-/commit/87c64fc5b0db9f62f4e361444f4b60501ebf67b9