Fedora Account System
Red Hat Associate
Red Hat Customer
The X.org X11 server has a format string vulnerability in the os/log.c:LogFilePrep() function. A local user can exploit this by executing the Xorg binary with crafted arguments to read arbitrary memory and cause a crash.
Acknowledgments: Name: Narendra Shinde
Upstream is currently not fixing this issue in LogFilePrep(), as the file name passed to the function is expected to optionally contain format specifier %s. The following comment-only change was made to explicitly note this expectation: https://gitlab.freedesktop.org/xorg/xserver/commit/da15c7413916f754708c62c2089265528cd661e2 With the fix for CVE-2018-14665 (bug 1637761) applied, Xorg no longer allows -logfile option to be specified when running with elevated privileges, preventing exploitation of this flaw. The root user would still be able to trigger crash or memory disclosure using this bug, but that does not cross any trust boundary and hence has not security impact.
Public now via a blog post from the original reporter, primarily written for CVE-2018-14665: https://www.securepatterns.com/2018/10/cve-2018-14665-xorg-x-server.html
As explained in comment 4 above, this has no security impact after the fix for CVE-2018-14665 is applied, and hence is not planned to be addressed as a security flaw.