MGASA-2017-0269
Dashboard / Vulnerabilities / MGASA-2017-0269
MGASA-2017-0269
Summary: Updated x11-server packages fix security vulnerabilities
Details: Eric Sesterhenn discovered that the X.Org X server incorrectly compared MIT cookies. An attacker could possibly use this issue to perform a timing attack and recover the MIT cookie (CVE-2017-2624). It was discovered that the X.Org X server incorrectly handled endianness conversion of certain X events. An attacker able to connect to an X server, either locally or remotely, could use this issue to crash the server, or possibly execute arbitrary code as an administrator (CVE-2017-10971). It was discovered that the X.Org X server incorrectly handled endianness conversion of certain X events. An attacker able to connect to an X server, either locally or remotely, could use this issue to possibly obtain sensitive information (CVE-2017-10972). Use-after-free issue in an unused function in XDM (boo#1025035).
References: https://advisories.mageia.org/MGASA-2017-0269.html, https://bugs.mageia.org/show_bug.cgi?id=21191, https://lists.opensuse.org/opensuse-updates/2017-06/msg00070.html, https://usn.ubuntu.com/usn/usn-3362-1/, https://www.x41-dsec.de/lab/advisories/x41-2017-001-xorg/
Affected packages
Package
Name: x11-server
Purl: pkg:rpm/mageia/x11-server?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
