MGASA-2021-0573 - Updated x11-server packages fix security vulnerabilities

Publication date: 21 Dec 2021
URL: https://advisories.mageia.org/MGASA-2021-0573.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2021-4008,
     CVE-2021-4009,
     CVE-2021-4010,
     CVE-2021-4011

Updated x11-server packages fix security vulnerabilities:

The handler for the CompositeGlyphs request of the Render extension does
not properly validate the request length leading to out of bounds memory
write (CVE-2021-4008).

The handler for the CreatePointerBarrier request of the XFixes extension
does not properly validate the request length leading to out of bounds
memory write (CVE-2021-4009).

The handler for the Suspend request of the Screen Saver extension does
not properly validate the request length leading to out of bounds memory
write (CVE-2021-4010).

The handlers for the RecordCreateContext and RecordRegisterClients
requests of the Record extension do not properly validate the request
length leading to out of bounds memory write (CVE-2021-4011).

All of these issues can lead to local privileges elevation on systems
where the X server is running privileged and remote code execution for
ssh X forwarding sessions.

References:
- https://bugs.mageia.org/show_bug.cgi?id=29767
- https://lists.x.org/archives/xorg-announce/2021-December/003124.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4008
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4009
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4010
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4011

SRPMS:
- 8/core/x11-server-1.20.14-1.mga8

Mageia 2021-0573: x11-server security update

Updated x11-server packages fix security vulnerabilities: The handler for the CompositeGlyphs request of the Render extension does not properly validate the request length leading...

Summary

Updated x11-server packages fix security vulnerabilities:
The handler for the CompositeGlyphs request of the Render extension does not properly validate the request length leading to out of bounds memory write (CVE-2021-4008).
The handler for the CreatePointerBarrier request of the XFixes extension does not properly validate the request length leading to out of bounds memory write (CVE-2021-4009).
The handler for the Suspend request of the Screen Saver extension does not properly validate the request length leading to out of bounds memory write (CVE-2021-4010).
The handlers for the RecordCreateContext and RecordRegisterClients requests of the Record extension do not properly validate the request length leading to out of bounds memory write (CVE-2021-4011).
All of these issues can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.

References

- https://bugs.mageia.org/show_bug.cgi?id=29767

- https://lists.x.org/archives/xorg-announce/2021-December/003124.html

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4008

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4009

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4010

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4011

Resolution

MGASA-2021-0573 - Updated x11-server packages fix security vulnerabilities

SRPMS

- 8/core/x11-server-1.20.14-1.mga8

Severity
Publication date: 21 Dec 2021
URL: https://advisories.mageia.org/MGASA-2021-0573.html
Type: security
CVE: CVE-2021-4008, CVE-2021-4009, CVE-2021-4010, CVE-2021-4011

Related News