<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>x server Archives - Linux Windows and android Tutorials</title>
	<atom:link href="https://www.osradar.com/tag/x-server/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.osradar.com</link>
	<description>tutorials and news and Seurity</description>
	<lastBuildDate>Fri, 26 Oct 2018 17:11:43 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.8.12</generator>
	<item>
		<title>X.Org Bug allows Root Permission on Linux and BSD System</title>
		<link>https://www.osradar.com/x-org-bug-allows-root-permission-on-linux-and-bsd-system/</link>
					<comments>https://www.osradar.com/x-org-bug-allows-root-permission-on-linux-and-bsd-system/#respond</comments>
		
		<dc:creator><![CDATA[osradar_editor]]></dc:creator>
		<pubDate>Fri, 26 Oct 2018 17:11:43 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[x server]]></category>
		<category><![CDATA[x server bug]]></category>
		<category><![CDATA[x.org]]></category>
		<category><![CDATA[x.org bug]]></category>
		<guid isPermaLink="false">https://www.osradar.com/?p=6730</guid>

					<description><![CDATA[<p>X.Org is the open-source implementation of the “X Window System” that allows the GUI for our Linux and BSD systems. Recently, there’s a bug spotted that, if exploited, could allow privilege escalation of an execution to root level. The flaw is tracked as CVE-2018-14665. The bug is present for about 2 years in “xorg-server” (since [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/x-org-bug-allows-root-permission-on-linux-and-bsd-system/">X.Org Bug allows Root Permission on Linux and BSD System</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>X.Org is the open-source implementation of the “X Window System” that allows the GUI for our Linux and BSD systems. Recently, there’s a bug spotted that, if exploited, could allow privilege escalation of an execution to root level.</p>
<p>The flaw is tracked as CVE-2018-14665. The bug is present for about 2 years in “xorg-server” (since v1.19.0)!</p>
<h1>Privilege escalation and file overwrite</h1>
<p><img loading="lazy" class="size-full wp-image-6732 aligncenter" src="https://www.osradar.com/wp-content/uploads/2018/10/privilege.png" alt="" width="2084" height="490" srcset="https://www.osradar.com/wp-content/uploads/2018/10/privilege.png 2084w, https://www.osradar.com/wp-content/uploads/2018/10/privilege-300x71.png 300w, https://www.osradar.com/wp-content/uploads/2018/10/privilege-768x181.png 768w, https://www.osradar.com/wp-content/uploads/2018/10/privilege-1024x241.png 1024w, https://www.osradar.com/wp-content/uploads/2018/10/privilege-696x164.png 696w, https://www.osradar.com/wp-content/uploads/2018/10/privilege-1068x251.png 1068w, https://www.osradar.com/wp-content/uploads/2018/10/privilege-1786x420.png 1786w, https://www.osradar.com/wp-content/uploads/2018/10/privilege-1920x451.png 1920w" sizes="(max-width: 2084px) 100vw, 2084px" /></p>
<p>In an <a href="https://lists.x.org/archives/xorg-announce/2018-October/002927.html">advisory on the official website</a>, X.Org described the problem as an “incorrect command-line parameter validation”, allowing an attacker to overwrite files.</p>
<p>Using the “-modulepath” argument, it was possible to set an insecure path of modules that the X.Org server would load. File overwriting is possible with the “-logfile” argument.</p>
<h1>The bug was preventable in OpenBSD 6.4</h1>
<p><img loading="lazy" class="size-full wp-image-6733 aligncenter" src="https://www.osradar.com/wp-content/uploads/2018/10/preventable.gif" alt="" width="600" height="400" /></p>
<p>OpenBSD is the open-source implementation of the BSD system with a strong focus on security. Interestingly, this distro uses “xorg”. On the latest release (v6.4), the bug was inside the system. This was preventable.</p>
<p>According to the founder and leader of OpenBSD, Theo de Raadt, said that X maintainers knew about the bug since October 11. However, they noticed the OpenBSD devs after a week of releasing their new OS. If they knew about the issue, they would have taken steps for mitigating the problem or even would delay the release a week or two.</p>
<p>There’s already a remedy, though. OpenBSD project provides a <a href="https://ftp.openbsd.org/pub/OpenBSD/patches/6.4/common/001_xserver.patch.sig">source code patch</a> that requires compiling the code and rebuilding the X server. For a quick fix, users can disable the X server binary. Run the following command –</p>
<p>Besides OpenBSD, the bug also affects other Linux distros like Debian, Ubuntu, Fedora, RHEL, CentOS and their derivatives.</p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/x-org-bug-allows-root-permission-on-linux-and-bsd-system/">X.Org Bug allows Root Permission on Linux and BSD System</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.osradar.com/x-org-bug-allows-root-permission-on-linux-and-bsd-system/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
