Updated x11-server packages fix security vulnerabilities
Publication date: 21 Dec 2021Modification date: 21 Dec 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-4008 , CVE-2021-4009 , CVE-2021-4010 , CVE-2021-4011
Description
Updated x11-server packages fix security vulnerabilities: The handler for the CompositeGlyphs request of the Render extension does not properly validate the request length leading to out of bounds memory write (CVE-2021-4008). The handler for the CreatePointerBarrier request of the XFixes extension does not properly validate the request length leading to out of bounds memory write (CVE-2021-4009). The handler for the Suspend request of the Screen Saver extension does not properly validate the request length leading to out of bounds memory write (CVE-2021-4010). The handlers for the RecordCreateContext and RecordRegisterClients requests of the Record extension do not properly validate the request length leading to out of bounds memory write (CVE-2021-4011). All of these issues can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
References
- https://bugs.mageia.org/show_bug.cgi?id=29767
- https://lists.x.org/archives/xorg-announce/2021-December/003124.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4008
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4009
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4010
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4011
SRPMS
8/core
- x11-server-1.20.14-1.mga8