Advisories ยป MGASA-2020-0350

Updated x11-server packages fix security vulnerabilities

Publication date: 27 Aug 2020
Modification date: 27 Aug 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-14345 , CVE-2020-14346 , CVE-2020-14361 , CVE-2020-14362

Description

The handler for the XkbSetNames request does not validate the request length
before accessing its contents (CVE-2020-14345).

An integer underflow exists in the handler for the XIChangeHierarchy request
(CVE-2020-14346).

An integer underflow exist in the handler for the XkbSelectEvents request
(CVE-2020-14361).

An integer underflow exist in the handler for the CreateRegister request of
the X record extension (CVE-2020-14362).

The x11-server package has been updated to version 1.20.9, fixing these issues
and other bugs.
                

References

SRPMS

7/core