MGASA-2021-0219
Dashboard / Vulnerabilities / MGASA-2021-0219
Summary: Updated libx11 packages fix a security vulnerability
Details: XLookupColor() and other X libraries function lack proper validation of the length of their string parameters. If those parameters can be controlled by an external application (for instance a color name that can be emitted via a terminal control sequence) it can lead to the emission of extra X protocol requests to the X server (CVE-2021-31535).
References: https://advisories.mageia.org/MGASA-2021-0219.html, https://bugs.mageia.org/show_bug.cgi?id=28940, https://lists.x.org/archives/xorg-announce/2021-May/003088.html, https://lists.x.org/archives/xorg-announce/2021-May/003089.html, https://www.openwall.com/lists/oss-security/2021/05/18/3
Affected packages
Package
Name: libx11
Purl: pkg:rpm/mageia/libx11?arch=source&distro=mageia-7
Affected ranges
Type: ECOSYSTEM
Events:
