MGASA-2021-0573
Dashboard / Vulnerabilities / MGASA-2021-0573
MGASA-2021-0573
Summary: Updated x11-server packages fix security vulnerabilities
Details: Updated x11-server packages fix security vulnerabilities: The handler for the CompositeGlyphs request of the Render extension does not properly validate the request length leading to out of bounds memory write (CVE-2021-4008). The handler for the CreatePointerBarrier request of the XFixes extension does not properly validate the request length leading to out of bounds memory write (CVE-2021-4009). The handler for the Suspend request of the Screen Saver extension does not properly validate the request length leading to out of bounds memory write (CVE-2021-4010). The handlers for the RecordCreateContext and RecordRegisterClients requests of the Record extension do not properly validate the request length leading to out of bounds memory write (CVE-2021-4011). All of these issues can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
References: https://advisories.mageia.org/MGASA-2021-0573.html, https://bugs.mageia.org/show_bug.cgi?id=29767, https://lists.x.org/archives/xorg-announce/2021-December/003124.html
Affected packages
Package
Name: x11-server
Purl: pkg:rpm/mageia/x11-server?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
