CVE-2020-14344: Canonical Ubuntu Linux
Medium severity, CVSS 6.7. EPSS: 0.5% chance of exploitation in the next 30 days.
An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when setuid programs call XIM client functions while running with elevated privileges. No such programs are shipped with Red Hat Enterprise Linux.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 20.04 only
- Fedoraproject Fedora: version 31 only; version 32 only; version 33 only
- Opensuse Leap: version 15.1 only; version 15.2 only
- X.org LIBX11: before 1.6.10 (fixed in 1.6.10)
Published 2020-08-05. Last modified 2026-06-17.