Mageia 2020-0350: x11-server security update
Summary
The handler for the XkbSetNames request does not validate the request length
before accessing its contents (CVE-2020-14345).
An integer underflow exists in the handler for the XIChangeHierarchy request
(CVE-2020-14346).
An integer underflow exist in the handler for the XkbSelectEvents request
(CVE-2020-14361).
An integer underflow exist in the handler for the CreateRegister request of
the X record extension (CVE-2020-14362).
The x11-server package has been updated to version 1.20.9, fixing these issues
and other bugs.
References
- https://bugs.mageia.org/show_bug.cgi?id=27206
- https://lists.x.org/archives/xorg-announce/2020-August/003059.html
- https://lists.x.org/archives/xorg-announce/2020-August/003058.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14345
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14346
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14361
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14362
Resolution
MGASA-2020-0350 - Updated x11-server packages fix security vulnerabilities
SRPMS
- 7/core/x11-server-1.20.9-1.mga7