Advisories ยป MGASA-2020-0335

Updated x11-server packages fix security vulnerability

Publication date: 18 Aug 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-14347

Description

Allocation for pixmap data in AllocatePixmap() does not initialize the memory
in xserver, it leads to leak uninitialize heap memory to clients. When the X
server runs with elevated privileges. This flaw can lead to ASLR bypass, which
when combined with other flaws (known/unknown) could lead to lead to privilege
elevation in the client (CVE-2020-14347).
                

References

SRPMS

7/core