MGASA-2018-0377
Dashboard / Vulnerabilities / MGASA-2018-0377
MGASA-2018-0377
Summary: Updated libx11 packages fix security vulnerabilities
Details: Updated libx11 packages fix security vulnerabilities: An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in which the first string overflows, causing a variable to be set to NULL that will be freed later on, leading to DoS (segmentation fault) (CVE-2018-14598). An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unspecified other impact (CVE-2018-14599). An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as signed instead of unsigned, resulting in an out-of-bounds write (of up to 128 bytes), leading to DoS or remote code execution (CVE-2018-14600).
References: https://advisories.mageia.org/MGASA-2018-0377.html, https://bugs.mageia.org/show_bug.cgi?id=23474, https://openwall.com/lists/oss-security/2018/08/21/6, https://lists.opensuse.org/opensuse-updates/2018-08/msg00164.html, https://usn.ubuntu.com/3758-1/
Affected packages
Package
Name: libx11
Purl: pkg:rpm/mageia/libx11?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
