Bug 1638570 - xorg-x11-server: Format string vulnerability in os/log.c:LogFilePrep() allows for memory disclosure and crash
Summary: xorg-x11-server: Format string vulnerability in os/log.c:LogFilePrep() allows...
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1638572
TreeView+ depends on / blocked
 
Reported: 2018-10-11 23:55 UTC by Sam Fowler
Modified: 2021-02-16 22:57 UTC (History)
13 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2018-10-26 07:03:20 UTC
Embargoed:


Attachments (Terms of Use)

Description Sam Fowler 2018-10-11 23:55:10 UTC
The X.org X11 server has a format string vulnerability in the os/log.c:LogFilePrep() function. A local user can exploit this by executing the Xorg binary with crafted arguments to  read arbitrary memory and cause a crash.

Comment 1 Sam Fowler 2018-10-11 23:55:13 UTC
Acknowledgments:

Name: Narendra Shinde

Comment 4 Tomas Hoger 2018-10-25 14:42:51 UTC
Upstream is currently not fixing this issue in LogFilePrep(), as the file name passed to the function is expected to optionally contain format specifier %s.  The following comment-only change was made to explicitly note this expectation:

https://gitlab.freedesktop.org/xorg/xserver/commit/da15c7413916f754708c62c2089265528cd661e2

With the fix for CVE-2018-14665 (bug 1637761) applied, Xorg no longer allows -logfile option to be specified when running with elevated privileges, preventing exploitation of this flaw.  The root user would still be able to trigger crash or memory disclosure using this bug, but that does not cross any trust boundary and hence has not security impact.

Comment 5 Tomas Hoger 2018-10-26 06:58:06 UTC
Public now via a blog post from the original reporter, primarily written for CVE-2018-14665:

https://www.securepatterns.com/2018/10/cve-2018-14665-xorg-x-server.html

Comment 6 Tomas Hoger 2018-10-26 07:03:20 UTC
As explained in comment 4 above, this has no security impact after the fix for CVE-2018-14665 is applied, and hence is not planned to be addressed as a security flaw.


Note You need to log in before you can comment on or make changes to this bug.