Advisories ยป MGASA-2017-0366

Updated x11-server packages fix security vulnerabilities

Publication date: 09 Oct 2017
Modification date: 09 Oct 2017
Type: security
Affected Mageia releases : 5 , 6
CVE: CVE-2017-13721 , CVE-2017-13723

Description

In Xext/shm, the shmseg resource id can belong to a non-existing client
and abort X server with FatalError "client not in use", or overwrite
existing segment of another existing client (CVE-2017-13721).

Generating strings for XKB data used a single shared static buffer,
which offered several opportunities for errors when strings end up
longer than anticipated (CVE-2017-13723).
                

References

SRPMS

5/core

6/core