A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4328-1 | xorg-server security update |
EUVD |
EUVD-2018-6560 | A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges. |
Ubuntu USN |
USN-3802-1 | X.Org X server vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 29 Aug 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
X.org x Server
|
|
| CPEs | cpe:2.3:a:x.org:x_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
X.org xorg-server
|
X.org x Server
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T09:38:13.000Z
Reserved: 2018-07-27T00:00:00.000Z
Link: CVE-2018-14665
No data.
Status : Modified
Published: 2018-10-25T20:29:00.250
Modified: 2025-08-29T13:42:30.557
Link: CVE-2018-14665
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN