MGASA-2022-0256
Dashboard / Vulnerabilities / MGASA-2022-0256
Summary: Updated x11-server packages fix security vulnerabilities
Details: Updated x11-server packages fix security vulnerabilities: ProcXkbSetGeometry Out-Of-Bounds Access. The handler for the ProcXkbSetGeometry request of the Xkb extension does not properly validate the request length leading to out of bounds memory write (CVE-2022-2319). ProcXkbSetDeviceInfo Out-Of-Bounds Access. The handler for the ProcXkbSetDeviceInfo request of the Xkb extension does not properly validate the request length leading to out of bounds memory write (CVE-2022-2320).
References: https://advisories.mageia.org/MGASA-2022-0256.html, https://bugs.mageia.org/show_bug.cgi?id=30628, https://lists.x.org/archives/xorg/2022-July/061035.html
Affected packages
Package
Name: x11-server
Purl: pkg:rpm/mageia/x11-server?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
