MGASA-2017-0366
Dashboard / Vulnerabilities / MGASA-2017-0366
MGASA-2017-0366
Summary: Updated x11-server packages fix security vulnerabilities
Details: In Xext/shm, the shmseg resource id can belong to a non-existing client and abort X server with FatalError "client not in use", or overwrite existing segment of another existing client (CVE-2017-13721). Generating strings for XKB data used a single shared static buffer, which offered several opportunities for errors when strings end up longer than anticipated (CVE-2017-13723).
References: https://advisories.mageia.org/MGASA-2017-0366.html, https://bugs.mageia.org/show_bug.cgi?id=21820, http://openwall.com/lists/oss-security/2017/10/04/10
Affected packages
Package
Name: x11-server
Purl: pkg:rpm/mageia/x11-server?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
