CVE-2020-25697

A privilege escalation flaw was found in the Xorg-x11-server due to a lack of authentication for X11 clients. This flaw allows an attacker to take control of an X application by impersonating the server it is expecting to connect to.
Configurations

Configuration 1 (hide)

cpe:2.3:a:x.org:x_server:-:*:*:*:*:*:*:*

History

12 Feb 2023, 23:40

Type Values Removed Values Added
References
  • {'url': 'https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E', 'name': '[mina-dev] 20210225 [jira] [Created] (FTPSERVER-500) Security vulnerability in common/lib/log4j-1.2.17.jar', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'MLIST'}
  • (MISC) https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E -

31 Mar 2022, 16:57

Type Values Removed Values Added
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1895295 - (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1895295 - Issue Tracking, Third Party Advisory

10 Jan 2022, 15:15

Type Values Removed Values Added
References
  • {'url': 'http://www.openwall.com/lists/oss-security/2020/11/09/3,', 'name': 'http://www.openwall.com/lists/oss-security/2020/11/09/3,', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1895295,', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1895295,', 'tags': ['Broken Link'], 'refsource': 'MISC'}
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1895295 -

03 Jun 2021, 15:21

Type Values Removed Values Added
CPE cpe:2.3:a:x.org:x_server:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 4.4
v3 : 7.0
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1895295, - (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1895295, - Broken Link
References (MISC) https://seclists.org/oss-sec/2020/q4/105 - (MISC) https://seclists.org/oss-sec/2020/q4/105 - Mailing List, Third Party Advisory
References (MLIST) http://www.openwall.com/lists/oss-security/2020/11/09/3 - (MLIST) http://www.openwall.com/lists/oss-security/2020/11/09/3 - Mailing List, Third Party Advisory
References (MISC) http://www.openwall.com/lists/oss-security/2020/11/09/3, - (MISC) http://www.openwall.com/lists/oss-security/2020/11/09/3, - Mailing List, Third Party Advisory
References (MLIST) https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E - (MLIST) https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E - Mailing List, Third Party Advisory

26 May 2021, 13:33

Type Values Removed Values Added
CWE CWE-306

26 May 2021, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-05-26 13:15

Updated : 2023-12-10 13:55


NVD link : CVE-2020-25697

Mitre link : CVE-2020-25697

CVE.ORG link : CVE-2020-25697


JSON object : View

Products Affected

x.org

  • x_server
CWE
CWE-306

Missing Authentication for Critical Function