Advisories ยป MGASA-2021-0573

Updated x11-server packages fix security vulnerabilities

Publication date: 21 Dec 2021
Modification date: 21 Dec 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-4008 , CVE-2021-4009 , CVE-2021-4010 , CVE-2021-4011

Description

Updated x11-server packages fix security vulnerabilities:

The handler for the CompositeGlyphs request of the Render extension does
not properly validate the request length leading to out of bounds memory
write (CVE-2021-4008).

The handler for the CreatePointerBarrier request of the XFixes extension
does not properly validate the request length leading to out of bounds
memory write (CVE-2021-4009).

The handler for the Suspend request of the Screen Saver extension does
not properly validate the request length leading to out of bounds memory
write (CVE-2021-4010).

The handlers for the RecordCreateContext and RecordRegisterClients
requests of the Record extension do not properly validate the request
length leading to out of bounds memory write (CVE-2021-4011).

All of these issues can lead to local privileges elevation on systems
where the X server is running privileged and remote code execution for
ssh X forwarding sessions.
                

References

SRPMS

8/core